boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-93345

MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0049   39.8     —
AFFECTED
  Product   Versions     Fixed
  RouterOS  unspecified  7.25beta4
TIMELINE
  Sep 17  Reserved by VulnCheck
  Sep 22  Published (CNA: VulnCheck)
  Sep 24  PATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4.
CWE-1284 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Awaiting Analysis

Description

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with a negative-length address portion. Attackers can repeatedly send a single BGP UPDATE packet carrying a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to indefinitely hold down the BGP plane, causing session termination without a NOTIFICATION and triggering a service malfunction on the device. The fix is carried only in 7.25beta4, a development build; the current stable release 7.24.2 and the current long-term release 7.23.5 both remain affected.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 17, 2026ReservedReserved by VulnCheck
September 22, 2026PublishedPublished (CNA: VulnCheck)
September 24, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
MikroTikRouterOS——7.25beta4

Weaknesses

CWE-1284

References (2)

Related

Authoritative record: CVE-2026-93345 at cve.org

Vendors: mikrotik

Weaknesses: CWE-1284

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-93345 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.