CISA Warns of Critical Pre-Authentication RCE Vulnerability in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning about a critical vulnerability in MikroTik RouterOS that could allow an unauthenticated remote attacker to execute code with root privileges or cause a denial-of-service condition.
CVE-2026-84411 affects RouterOS web management
Tracked as CVE-2026-84411, the security issue is a pre-authentication integer underflow in RouterOS’ web management HTTP request processing.
According to CISA, a single specially crafted request could trigger arbitrary code execution with root privileges or cause a denial of service.
“The Web Management Service in affected RouterOS versions contains an integer underflow in the processing of reachable HTTP request bodies before authentication.” Read the CISA alert.
“This could be exploited by an unauthenticated network attacker to execute arbitrary code as root or cause a denial of service using a single crafted request.”
CISA recommends protecting internet-exposed MikroTik devices
CISA said it is not aware of CVE-2026-84411 being actively exploited. However, the agency has issued recommendations warning organizations about the risk and encouraging them to take protective measures.
CISA currently states that MikroTik RouterOS versions prior to 7.24 are affected. The agency also said vendors recommend updating to version 7.23 or later to reduce the risk.
For reference, the latest stable version of MikroTik RouterOS is 7.24.4, while the latest long-term release is 7.23.7. Both versions have been available since September 16.
Because the affected-version guidance is unclear, users should review CISA’s advisory and MikroTik’s future guidance before determining whether their devices are protected.
BleepingComputer has contacted both MikroTik and CISA for clarification about the RouterOS versions affected by CVE-2026-84411 but had not received a response at the time of publication. MikroTik has not yet published a security advisory about the vulnerability.
How to secure MikroTik RouterOS devices
CISA’s recommendations for MikroTik router owners include:
- Ensure that the control system is not accessible from the Internet.
- Place the control network and remote devices behind a firewall, and isolate them from the business network.
- Use an updated VPN for remote access and protect all connected devices.
MikroTik devices have been targeted in previous attacks
Although no active exploitation of CVE-2026-84411 has been made public, hackers and botnet malware often target MikroTik vulnerabilities.
Recently, Poland’s CERT agency warned that attackers took full control of devices with Internet-exposed SSH services by using exploit chains for two MikroTik RouterOS vulnerabilities, CVE-2026-67276 and CVE-2026-86060.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



