7.23.7 [long-term] is released!

Apparently, on OpenVPN for Android, they updated the GUI but not the underlying OpenVPN code then, since it appears to be deaf to "data-ciphers", and isn't correctly applying defaults either. Seems like changing such fundamental stuff like this is a "solution in search of a problem" and serves no purpose other than to break working configs . . . .

(And, fwiw, it doesn't have to be a command line option - this also applies in the config file)

CRS305-1G-4S new out of box upgrade from 7.14.x to this version failed.

netinstall required to recover.

Any OpenVPN command line option can appear in config file, the thing is that command line option has precedence...

Understood, it's just a lot less messy to NOT put it in the command . . . (and, there is no sign that this Android deployment does anything at the command line level . . . ).

On a wap ac, 7.23.7 with wifi-qcom-ac installs but it is not possible to enable the wifi-qcom-ac package (tried with reset as well, there was 56kb free space left). I had to upgrade to 7.24.4 to make wifi work again.

I can confirm my openvpn works on CHR 7.23.6 / aes-256-cbc, with many mikrotik clients connected.

Windows / iOS clients works too. Certificates generated by easyrsa/rsa3, not mikrotik.

2026-09-18 20:02:17 ovpn,info connection established from xxx, port: xxx
 to xxx
2026-09-18 20:02:18 ovpn,info xxx: using encoding - AES-256-CBC/SHA256

2026-09-18 20:02:18 ovpn,info,account xxx logged in, xxx from xxx
2026-09-18 20:02:18 ovpn,info : connected



/system/resource> print
uptime: 3d7h41m32s
version: 7.23.6 (long-term)
build-time: 2026-09-14 10:14:57
factory-software: 7.1
free-memory: 1770.6MiB
total-memory: 2048.0MiB
cpu: Intel(R)
cpu-count: 2
cpu-frequency: 2400MHz
cpu-load: 0%
free-hdd-space: 4.9GiB
total-hdd-space: 4.9GiB
write-sect-since-reboot: 13968
write-sect-total: 13968
architecture-name: x86_64
board-name: CHR QEMU Standard PC (i440FX + PIIX, 1996)
platform: MikroTik

In my situation:

HexS (RB760), new HexS (EU60) and 4011 went without issue. However problem starts with two RB5009. I completely lost access to GUI via winbox (i got information in winbox that username or password is wrong). Routers ware working ok but only possible access was via SSH. After downgrade to 7.23.5 ale come back to normal. Also i noticed that The Dude could not log in (via credentials which was working well on 7.23.5) to another routers on list. Routers (all spectrum of models) was responding to pings but The Dude was unable to login and gather routeos mode information (very usefull and much faster than SNMP). Downgrade and boom, everything works fine.

Seems that problem is related with arm64 because on MIPS and ARM based routers all was working fine.

Another thing. Can someone explain me why such updates come in stable and long term channel in same moment? It should be tested and verified in stable channel and than if all is ok, introduce to long term. I'm using long term to avoid such problems and keep environment in constant running.

Seriously Mikrotik? Seriously?

Let's dedicate this song to dev team in Mikrotik:

MikroTIk Bugs Are in the Air (Country) by SirBryan | Suno

A severe security issue (authentication) needed urgent patching across all versions. When things are done urgently, unexpected consequences sometimes emerge which may require further rapid patches. This happens with all software, all the time. If you work in cyber security, it's a daily task working out which urgent patches affect the estates you manage and which ones you can take a risk by delaying rollout.

Can you show me where here we have information that "severe security issue (authentication) needed urgent patching across all versions" is present in change log?

What's new in 7.23.6 (2026-09-14):

*) bgp - improve stability;
*) certificate - add "SSL.com Root Certification Authority ECC" to built-in root certificate authorities store;
*) certificate - allow importing a cross-signed certificate without replacing the existing one;
*) certificate - refactor certificate internal processes;
*) certificate - remove "GoDaddy Class 2 CA" from built-in root certificate authorities store;
*) console - improve stability;
*) crypto - improve stability (CVE-2026-67278);
*) ipsec - fix duplicate connections on IKEv2 retransmissions;
*) ipsec - improve stability;
*) leds - fix LEDs set to interface status staying off when the interface is active;
*) ppp - improve stability;
*) ptp - add manual configuration of PTP message intervals and per-port enabling and disabling;
*) ptp - fix PTP offset instability under heavy background multicast traffic;
*) ptp - fix PTP timestamps showing the wrong time on CRS510;
*) sfp - improve QSFP-DD breakout link establishing to NVIDIA DGX Spark and other devices;
*) system - improve stability;
*) user - improve failed login delay logic (CVE-2026-16347);
*) wifi - update radio regulatory information;
*) www - improve stability;

What's new in 7.23.7 (2026-09-16):

*) lte - prevent the modem firmware from being deleted for RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, EG25-G&SXTsq (introduced in 7.23.6);

If you have already upgraded to 7.23.6 or 7.24.3, follow these steps to restore LTE functionality on affected devices:

  1. Upgrade RouterOS to version 7.23.7 or 7.24.4

  2. Update the modem firmware:
    /interface/lte/firmware-upgrade [find] upgrade=yes

  3. Reboot the router.

For more details, see:
https://forum.mikrotik.com/t/warning-lte-interface-stops-working-after-upgrade-to-7-23-6-7-24-3

I don't see any urgent security patches here. Everything what i can see is this user - improve failed login delay logic (CVE-2026-16347). Maybe i don't work as CyberSec but i work with such people and Palo Alto or Cisco ASA didn't failed so hard after updates. If that was so urgent, it was so good that after update i wasn't able to login via winbox.

Urgent patch was 7.23.7 because Mikrotik made bug with some LTE, which i don't use in any of my devices. I don't have problem with patches and new releases but my problem is that it wasn't tested by MIkrotik and if i will have problem with one router, I will say that it' s coincident but two routers and same model which is pretty high in line up is nothing more than very poor testing and rushing software too fast to stable and long term channel. Same it was not so long time ago when HexS (RB760) ware looping (kernel panic) after start of openvpn. It was easy to test and find by Mikrotik. I know, i know that i should test each ROS in test lab but i can't reproduce every scenario in my environment. That's why i am on long term to have maybe older but risk free software.

This is why in for ex Cisco newest software has all new features but usually big companies choosing gold star one which is n-1 or sometimes n-2. If it was problem with security Mikrotik should put it in stable channel first wait, made information that new patch is first available on stable channel and than if all will be fine - move it to long term. Now i don't see any difference between stable and long term.

this maybe.

improve stability doesn't sound like urgent patch :wink:

It is one of CVE's published 2 weeks ago. Additional post-7.23.5 fixing related to this or what is going on?

CVE-2026-86060 is the privilege escalation flaw, that gained admin rights for the connection created using CVE-2026-67276 authentication bypass flaw. Both fixed in 7.23.4........... where they f**ked up dhcpv6 and fixed it in 7.23.5.

The new, CVE-2026-67278 and CVE-2026-16347 were fixed in 7.23.6........... where they f**ked up lte modems by deleting it's firmware and bricking it, fixed it in 7.23.7.

Now, with the CVE-2026-89028 SMB1 heap corruption vulnerability, another SMB CVE-2026-56719 out-of-bounds read vulnerability and CVE-2026-89021 container path traversal flaw, still unfixed in longterm.. no, I'm not installing 6.23.8, I'll wait whatever they f**k up this time and go with 6.23.9, fortunately I don't have SMB or containers active on my routers

Oh, and I forgot CVE-2025-56566, storing plaintext credentials in non-volatile storage

//edit - a stupid night time typo, of course I'm not thinking about installing 6.xx, I meant I'm not installing the incoming 7.23.8 and I'll wait for 7.23.9, lol, the post had entirely different meaning :grinning_face: I'm leaving the original text for consistence, since there were reactions to it

Riiight ... recent CVEs won't be the biggest problems when running 12+ years old ROS :wink:

I think is just a typo... not really 6.x

But 6.49.22, with last CVE fix, now exist:

Okay. Mikrotik just released a new 6.x long-term with just this single change. Still not convinced that it is important?

Urgency ... is subjective.

Some people think it's urgent to have fire alarms and handheld fire extinguishers in their homes. Some people don't ... and wait for handymen to rebuild their home after fire.

No joke - I know people who argue exactly like that: "I have fire insurance."

Are you reading my mind? That's near exactly what I was thinking...


I’m one of the few people I know who has fire extinguishers
and emergency lights at home, in every single room, plus 0.01A RCD in the bathroom and kitchen...
plus two 0.03A RCD, one below the other, from two different brands, after the electricity meter and the surge arresters...