CVE-2024-27686: High severity Mikrotik RouterOS (x86) vulnerability
Published May 8, 2026
·Updated
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.
Affected Software
1 affected component
Mikrotik RouterOS (x86)>=6.40.5<=6.49.10
Event History
May 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27686?
CVE-2024-27686 is considered a high severity vulnerability due to its potential to cause a denial of service by crashing the device.
2
How do I fix CVE-2024-27686?
To fix CVE-2024-27686, upgrade RouterOS from versions 6.40.5 to 6.49.10 to the patched version 7 or later.
3
What type of attack is associated with CVE-2024-27686?
CVE-2024-27686 allows a remote attacker to exploit the SMB service on TCP port 445, leading to device crashes.
4
Which versions of Mikrotik RouterOS are affected by CVE-2024-27686?
Versions 6.40.5 through 6.49.10 of Mikrotik RouterOS (x86) are affected by CVE-2024-27686.
5
What is the impact of CVE-2024-27686 on Mikrotik devices?
The impact of CVE-2024-27686 is a denial of service, which manifests as a crash of the affected Mikrotik devices.