CISA

MikroTik RouterOS

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.

The following versions of MikroTik RouterOS are affected:

RouterOS vers:all/* (CVE-2026-14227)

Vendor

Equipment

MikroTik

MikroTik RouterOS

Insufficient Session Expiration

Critical Infrastructure Sectors: Information Technology

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Latvia

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may...