CVE-2026-84411 — a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling — can allow a single crafted request to produce code execution with root privileges or cause a denial-of-service condition, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned.
CVE-2026-84411: the flaw and what CISA says
CISA describes CVE-2026-84411 as “an integer underflow in RouterOS’s web-management HTTP request handling” that is reachable before authentication. “This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request,” the agency wrote.
The agency said a single crafted request can produce code execution with root privileges or denial of service. Although CISA has “no knowledge of the vulnerability being actively exploited,” it issued the advisory to alert organizations and provide defensive measures.
MikroTik RouterOS versions: public statements and available releases
CISA notes that “MikroTik RouterOS versions below 7.24 are currently affected.” The agency also says that the vendor recommends updating “to version 7.23 or later to mitigate the risk.” The public record additionally shows that the latest stable RouterOS release is 7.24.4 and the most recent long-term release (LTR) is 7.23.7, both available since September 16.
BleepingComputer contacted both MikroTik and CISA “for clarification about the RouterOS versions affected by CVE-2026-84411,” but had not received a response as of publication. The vendor has not yet published a security advisory about this issue.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCISA’s defensive checklist for MikroTik router owners
CISA provided a short list of immediate defensive actions aimed at reducing exposure to CVE-2026-84411 and similar router flaws. The agency’s recommended steps include:
- Keep control systems inaccessible from the internet.
- Place control networks and remote devices behind firewalls, isolated from business networks.
- Use updated VPNs for remote access and secure all connected devices.
These measures are presented as network-level mitigations to limit an unauthenticated attacker’s ability to reach the vulnerable web-management interface.
Threat precedent: MikroTik as a recurring target and Poland’s CERT warning
The advisory places CVE-2026-84411 in a context where “hackers and botnet malware often target MikroTik flaws.” Poland’s CERT is cited as warning that attackers recently used an exploit chain of two MikroTik RouterOS vulnerabilities — CVE-2026-67276 and CVE-2026-86060 — “to take full control of devices with SSH services exposed to the internet.”
The combination of prior exploit chains and the public availability of RouterOS releases frames the new advisory as a timely alert: CISA is flagging a pre-authentication RCE vector that, if reached, can yield root privileges with a single request.
What this means for network operators, procurement leaders, and adversaries
- Network operators and security teams: They must reconcile CISA’s statement that versions below 7.24 are affected with the vendor’s recommendation to update to 7.23 or later; BleepingComputer sought clarification from both MikroTik and CISA and had not received a response. In the interim, teams can apply CISA’s network protections — block internet access to management interfaces, isolate control networks, and require VPNs for remote access — while inventorying RouterOS versions on devices.
- Procurement and asset managers: The availability of RouterOS 7.24.4 (stable) and 7.23.7 (LTR) since September 16 means there are published releases organizations can reference as they decide whether to update or replace affected devices. The vendor has not yet issued its own public advisory to resolve version guidance, a gap procurement teams will need to factor into risk calculations.
- Adversaries and botnet operators: The advisory reiterates a pattern already noted by Poland’s CERT: MikroTik flaws have been the basis for exploit chains that seize control of devices exposed to the internet. The new CISA alert highlights that an unauthenticated HTTP request could be sufficient to achieve root code execution, an attractive characteristic for rapid scanning and compromise efforts.
The record is clear on the technical risk: a reachable, pre-authentication integer underflow in RouterOS’s web-management handling can, in CISA’s words, “be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root.” What remains to be clarified publicly is exactly which RouterOS revisions fully remediate that risk; MikroTik has not yet published an advisory, and BleepingComputer’s request for clarification had not been answered. Until vendor guidance is available, CISA’s network-focused mitigations and the published RouterOS releases of 7.24.4 and 7.23.7 (available since September 16) form the concrete points administrators must weigh.
Source: BleepingComputer — CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS




