EUVD-2026-50017, CVE-2026-16347, GHSA-8v62-p5rj-72x6 - which RouterOS Version does fix that?

Just guessing from the changelog, the current long term 7.21.5 should have mitigation for that, as well as anything >= 7.22.

RouterOS 7.20 introduced this:

But it appears to be buggy, so there are additional fixes in 7.22:

As well as in 7.21.4 long-term: