Vulnerabilities & PatchesEmerging1 src
MikroTik RouterOS
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic. The following versions of MikroTik RouterOS are affected: RouterOS vers:all/* (CVE-2026-14227) CVSS Vendor Equipment Vulnerabilities
v3 4.9 MikroTik MikroTik RouterOS Insufficient Session Expiration
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Latvia
CVE-2026-14227