Apparently, on OpenVPN for Android, they updated the GUI but not the underlying OpenVPN code then, since it appears to be deaf to "data-ciphers", and isn't correctly applying defaults either. Seems like changing such fundamental stuff like this is a "solution in search of a problem" and serves no purpose other than to break working configs . . . .
(And, fwiw, it doesn't have to be a command line option - this also applies in the config file)
Understood, it's just a lot less messy to NOT put it in the command . . . (and, there is no sign that this Android deployment does anything at the command line level . . . ).
On a wap ac, 7.23.7 with wifi-qcom-ac installs but it is not possible to enable the wifi-qcom-ac package (tried with reset as well, there was 56kb free space left). I had to upgrade to 7.24.4 to make wifi work again.
HexS (RB760), new HexS (EU60) and 4011 went without issue. However problem starts with two RB5009. I completely lost access to GUI via winbox (i got information in winbox that username or password is wrong). Routers ware working ok but only possible access was via SSH. After downgrade to 7.23.5 ale come back to normal. Also i noticed that The Dude could not log in (via credentials which was working well on 7.23.5) to another routers on list. Routers (all spectrum of models) was responding to pings but The Dude was unable to login and gather routeos mode information (very usefull and much faster than SNMP). Downgrade and boom, everything works fine.
Seems that problem is related with arm64 because on MIPS and ARM based routers all was working fine.
Another thing. Can someone explain me why such updates come in stable and long term channel in same moment? It should be tested and verified in stable channel and than if all is ok, introduce to long term. I'm using long term to avoid such problems and keep environment in constant running.
A severe security issue (authentication) needed urgent patching across all versions. When things are done urgently, unexpected consequences sometimes emerge which may require further rapid patches. This happens with all software, all the time. If you work in cyber security, it's a daily task working out which urgent patches affect the estates you manage and which ones you can take a risk by delaying rollout.
Can you show me where here we have information that "severe security issue (authentication) needed urgent patching across all versions" is present in change log?
What's new in 7.23.6 (2026-09-14):
*) bgp - improve stability;
*) certificate - add "SSL.com Root Certification Authority ECC" to built-in root certificate authorities store;
*) certificate - allow importing a cross-signed certificate without replacing the existing one;
*) certificate - refactor certificate internal processes;
*) certificate - remove "GoDaddy Class 2 CA" from built-in root certificate authorities store;
*) console - improve stability;
*) crypto - improve stability (CVE-2026-67278);
*) ipsec - fix duplicate connections on IKEv2 retransmissions;
*) ipsec - improve stability;
*) leds - fix LEDs set to interface status staying off when the interface is active;
*) ppp - improve stability;
*) ptp - add manual configuration of PTP message intervals and per-port enabling and disabling;
*) ptp - fix PTP offset instability under heavy background multicast traffic;
*) ptp - fix PTP timestamps showing the wrong time on CRS510;
*) sfp - improve QSFP-DD breakout link establishing to NVIDIA DGX Spark and other devices;
*) system - improve stability;
*) user - improve failed login delay logic (CVE-2026-16347);
*) wifi - update radio regulatory information;
*) www - improve stability;
What's new in 7.23.7 (2026-09-16):
*) lte - prevent the modem firmware from being deleted for RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, EG25-G&SXTsq (introduced in 7.23.6);
If you have already upgraded to 7.23.6 or 7.24.3, follow these steps to restore LTE functionality on affected devices:
Upgrade RouterOS to version 7.23.7 or 7.24.4
Update the modem firmware:
/interface/lte/firmware-upgrade [find] upgrade=yes
I don't see any urgent security patches here. Everything what i can see is this user - improve failed login delay logic (CVE-2026-16347). Maybe i don't work as CyberSec but i work with such people and Palo Alto or Cisco ASA didn't failed so hard after updates. If that was so urgent, it was so good that after update i wasn't able to login via winbox.
Urgent patch was 7.23.7 because Mikrotik made bug with some LTE, which i don't use in any of my devices. I don't have problem with patches and new releases but my problem is that it wasn't tested by MIkrotik and if i will have problem with one router, I will say that it' s coincident but two routers and same model which is pretty high in line up is nothing more than very poor testing and rushing software too fast to stable and long term channel. Same it was not so long time ago when HexS (RB760) ware looping (kernel panic) after start of openvpn. It was easy to test and find by Mikrotik. I know, i know that i should test each ROS in test lab but i can't reproduce every scenario in my environment. That's why i am on long term to have maybe older but risk free software.
This is why in for ex Cisco newest software has all new features but usually big companies choosing gold star one which is n-1 or sometimes n-2. If it was problem with security Mikrotik should put it in stable channel first wait, made information that new patch is first available on stable channel and than if all will be fine - move it to long term. Now i don't see any difference between stable and long term.
CVE-2026-86060 is the privilege escalation flaw, that gained admin rights for the connection created using CVE-2026-67276 authentication bypass flaw. Both fixed in 7.23.4........... where they f**ked up dhcpv6 and fixed it in 7.23.5.
The new, CVE-2026-67278 and CVE-2026-16347 were fixed in 7.23.6........... where they f**ked up lte modems by deleting it's firmware and bricking it, fixed it in 7.23.7.
Now, with the CVE-2026-89028 SMB1 heap corruption vulnerability, another SMB CVE-2026-56719 out-of-bounds read vulnerability and CVE-2026-89021 container path traversal flaw, still unfixed in longterm.. no, I'm not installing 6.23.8, I'll wait whatever they f**k up this time and go with 6.23.9, fortunately I don't have SMB or containers active on my routers
Oh, and I forgot CVE-2025-56566, storing plaintext credentials in non-volatile storage
//edit - a stupid night time typo, of course I'm not thinking about installing 6.xx, I meant I'm not installing the incoming 7.23.8 and I'll wait for 7.23.9, lol, the post had entirely different meaning I'm leaving the original text for consistence, since there were reactions to it
Some people think it's urgent to have fire alarms and handheld fire extinguishers in their homes. Some people don't ... and wait for handymen to rebuild their home after fire.
Are you reading my mind? That's near exactly what I was thinking...
I’m one of the few people I know who has fire extinguishers
and emergency lights at home, in every single room, plus 0.01A RCD in the bathroom and kitchen...
plus two 0.03A RCD, one below the other, from two different brands, after the electricity meter and the surge arresters...