yes, service "available-from" is also enough if that IP is trusted
I don’t believe it stems from mikrotik not caring, but rather from a false assumption that what they’re doing is truly the right thing to do in this situation.
In other words, it’s incompetence at its finest, essentially not understanding the problem at hand and the fact that the way they handle it ends up causing more harm.
One should always treat security updates as if the details about the patched vulnerabilities is widely available to those who want to exploit them. The only barriers you put by concealing it is on those who wish to protect and validate their own environment, rather than on those who wish to exploit it.
MikroTik is working with CERT and following any advice and course of action recommended by professionals.
Whatever it is - I would not want to be the one eating my hat over a bet that supportsec page will not have new entries before the end of 2026 ![]()
Entry is there since yesterday. Can eat that hat.
i do "rolling-release" style of updatig, whenever theres a new update in stable i update, i do tend to wait for a .1 or .2 update tho, i rarely update to 7.24 for example, unless theres something really critical for my setup thats fixed or updated.
They’re taking a page out of Kim Jong Un’s lawyers' playbook.
If it isn’t officially acknowledged, then officially, it never happened.
And if it officially didn’t happen, there are no grounds for legal action against them.
They also can’t be rejected by the US market for having CVEs.
They’re adopting a stance as noble as a cheater’s.
But they’re likely doing this quite deliberately.
And they’re probably managing to bypass the very mechanisms they want to bypass.
From CERT’s own guidence to vendors:
Many deployers rely on the vendor to provide clear and accurate information about the vulnerability and the fix in order to know that they need to take action. This information should be made available to the public as soon as the patch is available.
That information is provided here https://mikrotik.com/supportsec/september-2026-vulnerability/
What are they concealing from you that's needed to properly secure and defend? Update and secure your management plane.
One should always treat security updates as if the details about the patched vulnerabilities is widely available to those who want to exploit them. The only barriers you put by concealing it is on those who wish to protect and validate their own environment, rather than on those who wish to exploit it.
The only time this is true is when fixes to critical security issues go unannounced or they are obfuscated in vague language. If that were the case I would agree with you (they would be giving bad actors the upper hand). But that is not what is happening here. They've clearly announced it as a critical security issue, patched and pushed updates, gave users who cant update the appropriate remediation, and announced a CVE will follow.
What more do you want?
Let's face it, security issue or not, I've been saying the same thing for YEARS...
NEVER-OPEN-SERVICES-WAN-SIDE
But people don't listen and continue to leave Winbox, or even Telnet, open on the WAN side for absurd and stupid reasons.
If I offend someone, well, this person should ask self a few questions first instead of getting offended...
There's nothing more obvious than this. There's no way to be a network specialist without understanding this.
No, it explicitly saying otherwise:
To give time to update your systems, we are not currently publishing detailed information.
It is not enough to just acknowledge that you found a security vulnerability and fixed it, but it’s important to emphasize that said vulnerability is being exploited in the wild, and than to list what services it affects.
100% agree, and modern-talking "offending" (whatever it means) has nothing to do with that.
Its curious and ridiculous that when unsecured Cisco/Huawei/Juniper is found that means person who connected it to Internet is advised to quit job, hire somebody etc.
If MT device is found, thats always MT fault and blahblah ![]()
I've been wrong myself, but I certainly don't go around telling anyone...
To err is human, but doing stupid things isn't diabolical... It's stupid...
Accidentally, some holes may remain... no one is 100% perfect...
but doing them on purpose, and with conviction, well, you ask for them...
How about what services were affected? Under what configuration?
The fact that there is an ongoing in the wild exploitation of said vulnerability?
instead, they framed it as if they were the ones who found a critical vulnerability, when in practice it seems like they were made aware of the vulnerability from an active exploitation campaign.
Customers don’t need to keep pushing the vendor to get a tiny glimpse of information they eventually provide. It needs to be upfront, and more specific.
The problem is mainly due to peaple miss categorizing what claim is being made, and mixing 2 types of unrelated security failures.
Misconfiguration is to be blamed on the customer, the vendor has nothing to do with it.
Vulnerabilities on the other hand needs to be handled by the vendor, and in that case - they also need to properly disclose it and inform the customers, so that they can assess their own specific situation and take action.
Failing to do the second will always fall under the vendors fault. And that’s where mikrotik doesn’t take enough accountability.
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.
I do not find that way to communicate sufficient. I do understand that you want to give your users time to update their systems before the tsunami of attacks hits.
However, I feel that not specifying at all what we are looking for is not appropriate for a major vendor in the networking space! Even if you are not being specific, it should be possible to say more than "most configurations are not at risk". Is this due to something that was introduced in 7.24 or are older versions affected as well? Is this due to vulnerable Mikrotik management services being exposed? Is this because you discovered a bug in the DHCP client that can be exploited? "system - improve stability" can mean something major but can also mean nothing relevant at all.
For example: I couldn't care less about problems with BGP but would be very much concerned about security problems in your IPSec stack. Security by obscurity simply is no security. Especially not with all those really capable AI models around.
I would also kindly ask for a separate low traffic read-only forum exclusively for security announcements of this kind. I only read this note about this update being important because I was preparing the 7.24 rollout for next week. If that note had been in the release notes of 7.24.1 it might have gone unnoticed because that version was already superseded by 7.24.2.
Thank you for considering my concerns.
Well that sounds nice, but we need to have services like IPsec and layered stuff like GRE/IPsec and L2TP/IPsec open from internet. We can only pray that there are not so many bugs there as there are in admin interfaces.
Well, if what I wrote is not correctly understandable, I apologize,
but I meant the admin interfaces, not the VPNs...