7.26beta [development] is released!

Before an upgrade:

Remember to make backup/export files before an upgrade and save them on another storage device;
Make sure the device will not lose power during upgrade process;
Device has enough free storage space for all RouterOS packages to be downloaded.

What's new in 7.26beta1 (2026-10-01):

  • bridge - add a per-VLAN DHCP snooping option;
  • bridge - fix loop-protect not working when a VLAN interface is added to the bridge;
  • bridge - show if bridge port is blocked by dot1x;
  • bridge - store hw option for disabled bridge ports;
  • cmr - add initial implementation of centralised platform for RouterOS devices, allowing updates, monitoring, alerts and other options;
  • console - improve stability;
  • container - add /app menu to ARM32 devices;
  • crypto - improve ECDSA and EdDSA key and signature validation;
  • dhcpv4-client - improve stability when the interface is deactivated while the client broadcasts a DHCP release;
  • dhcpv6-server - add a dns-none option to not include DNS options in responses;
  • dhcpv6-server - fix a DHCPv6 server failure when the RADIUS reply contains an empty delegated IPv6 prefix;
  • dns - improve service stability on HTTP/2 DoH connections;
  • ethernet - improve stability on devices with Intel I226-V network controllers;
  • ethernet - move the port bandwidth setting to the switch port menu;
  • files - improve stability when moving directories to external storage;
  • interface - show if interface is blocked by stp or dot1x;
  • ipsec - fix IPsec tunnels failing after migration from the old QKD settings;
  • ipsec - fix IPsec tunnels not establishing when an address my-id is configured on the responder;
  • l3hw - add VRRP hardware offloading support;
  • log - add the container name to CEF logs;
  • lte - do not reconfigure if not RouterOS activated CID is deactivated for R11l-LTE7 modem;
  • lte - fix dialer for D-Link DWM-222W modems;
  • lte - fix IPv6 route not being added on modems that do not report a gateway via control interface;
  • lte - fix modem firmware-upgrade failing when SMS polling is enabled;
  • lte - fix multi-APN passthrough stopping when one APN fails to connect;
  • lte - fix multi-APN passthrough stopping when one passthrough-interface VLAN is down on the CPE in multi passthrough interface setup;
  • lte - fix passthrough cleanup when the lte link goes down for QMI modems;
  • lte - fix recurring LTE disconnects R11e-LTE-US modem and some Sierra modems;
  • lte - keep the "auto" MTU option on LTE interface after reboot;
  • lte - reworked multi-apn support. Added support for slave APN interface add/remove;
  • netinstall - install the package version of the configured update channel;
  • ovpn - improve stability in UDP Ethernet mode when the TX queue is full;
  • pim - fix a routing process failure when the hello-delay is set to 0;
  • ptp - fix PTP not working on a VLAN-aware bridge when IGMP snooping is enabled;
  • qos - fix per-queue counters after a switch restart (introduced in v7.23);
  • quickset - fix the WAN interface being selected incorrectly;
  • reverse-proxy - fix setting the VRF parameter for reverse-proxy rules via CLI;
  • switch - add interface-list support to port isolation;
  • switch - fix high CPU usage when removing switch VLANs on Atheros-based switch chips;
  • switch - fix switch rules not working on Atheros-based switch chips;
  • switch - fix switch rules port matchers not working on IPv6 traffic on Atheros-based switch chips;
  • switch - fix switch rules with rate limits stopping traffic on CRS3xx devices;
  • switch - improve stability on CRS326-24S+2Q+ devices;
  • system - improve stability;
  • system - stop the flash configuration store from growing on dynamic configuration changes;
  • webfig - add conditional coloring of cells in tables;
  • wifi - add a default-country parameter in radio settings (CLI only);
  • wifi - fix WPA3 SAE authentication issue for ECC group 21 (introduced in 7.24.3);
  • wifi - implement channel.reselect-interval feature for missing drivers;
  • wifi - reuse freed station association IDs;
  • wifi-mediatek - update the wireless driver and firmware;
  • wifi-qcom - fix antenna gain setting not affecting transmit power (introduced in v7.24);
  • winbox - add the interface column to the OSPF neighbor list;
  • winbox - rename "minimum-version" to "minimum-firmware" under "System/RouterBOARD" menu;
  • winbox - show warning messages under "System/Users/SSH Keys" and "System/Users/SSH Private Keys" menu;
  • wireguard - do not show an interface as running when it has no peers;
  • wireguard - fix a client-dns value that could not be removed in WinBox;
  • wireguard - fix a peer that would not work after import when no endpoint address is set;

To upgrade, click Check For Updates under System/Packages menu and select the testing Channel in RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download

  • Everything went smoothly
  • I encountered an issue after the update (please post about the device, configuration, and unexpected symptoms)a
  • I encountered an issue, but solved it (please post the solution)
0 voters

If you experience version related issues, then please send supout file from your router to support@mikrotik.com. The file must be generated while a router is not working as suspected or after some problem has appeared on the device

Please keep this forum topic strictly related to this particular RouterOS release.

Not a single MLAG fix in 7.26beta1 despite all the recent reports??

dns - improve service stability on HTTP/2 DoH connections;

Very good! Would it be relevant to connection multiplexing?

Nice!!

I really hope, to the point i almost beg for the DoH with Quad9 works. Spent 2 weeks troubleshooting, going back and forth with support, I'm sure mister Glebs bless his heart had enough of me for a lifetime.

Doing everything by the book, bootstrapping DoH, inputting the correct domain and the correct server ip's for Quad9, using traffic captures to troubleshoot the dns, warning DoH server response not OK: 0: logs repeating all the time made me lose some years of my life. I'm not 100% convinced this is not a mikrotik issue but i am about 85% there, Quad9 isn't too reliable.

In the end i ended up switching to CloudFlare and it just worked.

However the dns - improve service stability on HTTP/2 DoH connections; gives me hope.

Hope someone gonna test it and give feedback, because I'm good with DNS for a bit.

Thanks for fixing! I observed this behavior but thought it happened on purpose. :smiley:

Big news! cmr comes as separate nkg. That's great to see new packages are introduced (e.g. netinstall, cmr) instead of growing the base package. :+1: Metadata says "CMR server", so this is a service you only install once in your network and can manage other devices. Right?

Also nice! I already recognized the larger container npk in 7.24 with new binary inside. So now it is official.

What is it actually?

Please note that this, as the changelog states, is "initial implementation" or WIP of CMR. Things will improve and adapt - some things are available only through WebFig and not through WInBox yet, etc. Finally we can tell why WInBox 4 was required as minimal supported version as well! :slight_smile:

  • The server runs on a device with the cmr package. The client is part of RouterOS, so every device can be a client,

except devices with the smips and powerpc architecture.

First impression of the WebFig Controller dashboard: very good for an "initial implementation"! Keep it coming!

Regarding WinBox 4:

Do I need to clear any caches? There are some icons missing.

Thank you very much!

Can this be a signal to hope to flowspec?

What a-holes... :face_with_symbols_on_mouth: (just kidding!)

but you should've said so sooner... There would have been less controversy...

:upside_down_face: "I like Winbox 4" if is it the price...

7.26beta1 has the same issues I reported on 7.25rc1 [testing] is released! - #11 by CTassisF.

SUP-225393

Except also SwOS... for now...

fail-policy=continue skips a failed device and continues with the rest. fail-policy defaults to continue when unset. The other fail policies are stop and continue-order.

NO!

MUST be fail-policy=stop the default...

For most of the functionality of CMR, we suggest using Webfig right now, it has more features, like maps.

... and mipsbe.

EDIT: nevermind, see table by rextended below:

Seriously?

90% of all my CPEs are mipsbe...