Remember to make backup/export files before an upgrade and save them on another storage device;
Make sure the device will not lose power during upgrade process;
Device has enough free storage space for all RouterOS packages to be downloaded.
What's new in 6.49.22 (2026-09-16):
system - improve stability (includes CVE-2026-67281);
To upgrade, click Check For Updates under System/Packages menu and select the long term Channel in RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download
Everything went smoothly
I encountered an issue after the update (please post about the device, configuration, and unexpected symptoms)
I encountered an issue, but solved it (please post the solution)
0voters
If you experience version related issues, then please send supout file from your router to support@mikrotik.com. The file must be generated while a router is not working as suspected or after some problem has appeared on the device
Please keep this forum topic strictly related to this particular RouterOS release.
Since the 3rd, there have already been four releases for the long-term chain.
And all these security issues were already known back on the 3rd.
And now we’re getting another release?
If I understand correctly...
There are still active vulnerabilities right now that could be exploited if not contained.
And back on the 3rd—when the first fix was released—they already knew about all these vulnerabilities and how to fix them.
What was missing was organization and internal communication—someone with a bit more composure to hold off and release a fix a day or two later that addressed everything at once.
Is that right?
I hope the question was not for me as I do not know. I read the CVE but I find the info strange as it only discuss V7 and this CVE number is not patched in V7 yet so either the CVE is wrong or we will soon see a patch in V7 as well.
Regardless I think the takeaway here should be proctect you admin interfaces on your devices. Do not expose webfig, winbox or anything like this on internet unless you have a protection lay ontop.
Also prepare youself for more pacthes as AI code check will for sure create more patches in the future but sooner or later they will also die out but before that the road will be bumpy so if you want to patch less in the future protect your admin interfaces
it was fixed in 7.23.4 in the big bunch, but since mikrotik is lying about it, people are confused.
Btw - they first announced it was fixed in 6.49.21 and 7.23.4, then they changed it to "ROS 7.x affected only" and then - voila, 6.49.22 went out, fixing exactly this.
The communication, or better say miscommunication about this from Mikrotik is terrible
Was the vulnerability resolved in 6.49.21 or is 6.49.22 required to completely mitigate the vulnerability?
The CVE listing shows that 6.x was not impacted, yet the email stated to patch to 6.49.21 and now this is stating it resolves a CVE for 6.x which the CVE states it does not apply. Do we need to patch again from 6.49.21 to 6.49.22 to ensure we are protected? Our management isn't publicly accessible, the concern is any other compromise could leverage this CVE to access the firewall from an internal interface.
MikroTik addressed the flaw in RouterOS 7.23.4 (Long-term) and 7.24.2 (Stable). Release details are published in the 7.23.4 release notes and 7.24.2 release notes. No fix is available for the 6.x branch because it is not affected.