Skip to content

CISA flags pre-auth root RCE in MikroTik RouterOS (CVE-2026-84411)

CISA warns of CVE-2026-84411, a CVSS 9.8 pre-auth integer underflow in RouterOS web management that yields root code execution. Fixed in 7.24 and 7.23.7 LTS; no known exploitation yet.

Published 2 min read

CISA is warning of CVE-2026-84411, a CVSS 9.8 pre-authentication flaw in MikroTik RouterOS that lets an unauthenticated attacker run code as root with a single crafted HTTP request. The agency says it has no knowledge of exploitation yet — it published the advisory to get organizations ahead of it.

The primary reference is CISA's ICS advisory ICSA-26-272-06, published September 29; the flaw is tracked at CVE-2026-84411. As of the initial reporting by BleepingComputer, MikroTik had not published its own advisory.

What the bug does

The vulnerability is an integer underflow in the RouterOS web-management HTTP request-body handling, reachable before authentication. Per the advisory, one crafted request can produce arbitrary code execution with root privileges, or a denial of service. The attack needs only network access to the management interface — no credentials, no user interaction, which is what puts it at the 9.8 ceiling.

Affected and fixed versions

  • Affected: RouterOS versions earlier than 7.24.
  • Fixed: RouterOS 7.24 on the stable branch (latest is 7.24.4) and 7.23.7 on the long-term (LTS) branch. Both have been available since September 16, 2026.

Exploitation status

None known. CISA states it "has no knowledge of the vulnerability being actively exploited" and issued the advisory as a precaution. No public proof-of-concept has surfaced at the time of writing.

Action checklist

  1. Upgrade RouterOS to 7.24+ (stable) or 7.23.7 (LTS), depending on the branch you run.
  2. Get the web management interface off the internet. The vulnerable surface is www/www-ssl — restrict it to a management VLAN or bind it to a VPN, don't expose it WAN-side.
  3. If you can't patch immediately, disable the web service (/ip service disable www,www-ssl) and use Winbox or SSH from a trusted network until you can.
  4. Audit exposure with a fingerprint query on Shodan/Censys for internet-facing RouterOS web UIs in your address space, and shut down anything that shouldn't be reachable.

Context

MikroTik edge routers have a long history as botnet fodder — their large internet-exposed install base and slow patch cadence make them a durable target, and a pre-auth root primitive is exactly the kind of bug that gets folded into automated scanning once a PoC lands. CISA moving first here, before any exploitation or even a vendor advisory, is the tell: patch on the assumption that the window between disclosure and mass exploitation of RouterOS bugs is short.

Related stories