Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-93345
MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N N N H 8.7 .0049 39.8 —
AFFECTED
Product Versions Fixed
RouterOS unspecified 7.25beta4
TIMELINE
Sep 17 Reserved by VulnCheck
Sep 22 Published (CNA: VulnCheck)
Sep 24 PATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4.
Description
MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with a negative-length address portion. Attackers can repeatedly send a single BGP UPDATE packet carrying a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to indefinitely hold down the BGP plane, causing session termination without a NOTIFICATION and triggering a service malfunction on the device. The fix is carried only in 7.25beta4, a development build; the current stable release 7.24.2 and the current long-term release 7.23.5 both remain affected.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 17, 2026 | Reserved | Reserved by VulnCheck |
| September 22, 2026 | Published | Published (CNA: VulnCheck) |
| September 24, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| MikroTik | RouterOS | — | — | 7.25beta4 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-93345 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.