NEWS

CISA Warns of Critical Pre-Auth RCE Flaw in MikroTik RouterOS

CISA warns of CVE-2026-84411, a critical CVSS 9.8 pre-auth flaw in MikroTik RouterOS letting unauthenticated attackers gain root RCE or crash the device.

Dylan H.

News Desk

September 30, 2026
7 min read
CISA Warns of Critical Pre-Auth RCE Flaw in MikroTik RouterOS

CISA Flags Third Critical MikroTik RouterOS Bug This Month

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS, tracked as CVE-2026-84411, that could let an unauthenticated attacker achieve remote code execution as root or trigger a denial-of-service condition. The flaw carries a CVSS v3.1 score of 9.8 (Critical) and a CVSS v4.0 score of 9.3 (Critical), and requires only a single, specially crafted HTTP request against an exposed RouterOS device — no login, credentials, or user interaction needed. CISA published the advisory, tracked as ICSA-26-272-06, on September 29, 2026, after an anonymous researcher reported the bug directly to the agency. It affects RouterOS builds earlier than 7.24, the same month CISA has already logged two other actively exploited MikroTik flaws — CVE-2026-67279 and CVE-2026-86060 — underscoring how heavily RouterOS-based infrastructure is being scrutinized right now.


Details

AttributeValue
CVE IDCVE-2026-84411
CISA AdvisoryICSA-26-272-06
Advisory PublishedSeptember 29, 2026
CVSS v3.1 Score9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0 Score9.3 (Critical)
CWE ClassificationCWE-191 — Integer Underflow (Wrap or Wraparound)
Vendor / ProductMikroTik RouterOS
Affected VersionsRouterOS builds earlier than 7.24
ComponentWeb management (HTTP) service
Authentication RequiredNone — reachable pre-authentication
Attack VectorNetwork, single crafted HTTP request
Reported ByAnonymous researcher (via CISA)
KEV StatusNot listed in CISA's Known Exploited Vulnerabilities catalog at time of publication
Known ExploitationNone confirmed; no public proof-of-concept identified
Patched InRouterOS 7.24 and later (latest builds: stable 7.24.4, long-term 7.23.7, both available since September 16, 2026)

How It Works

Root Cause

CVE-2026-84411 lives in RouterOS's web management service — the HTTP-based interface (Webfig) that administrators use for browser-based device configuration. According to CISA, the service contains an integer underflow in how it parses the body of incoming HTTP requests, and critically, that parsing logic runs before the service checks whether the requester is authenticated. An integer underflow occurs when an arithmetic operation produces a value below the minimum representable by its integer type, causing the value to wrap around to an unexpectedly large number — a class of bug (CWE-191) that frequently leads to out-of-bounds memory access, buffer miscalculation, or corrupted control-flow state once the wrapped value is used to size or index a buffer.

Exploitation Path

Because the flawed arithmetic executes ahead of any login check, an attacker needs no valid credentials, session token, or prior foothold on the device. CISA's advisory states the bug "can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service" — using a single crafted HTTP request sent to the exposed web management port. Successful exploitation for code execution would hand the attacker root-level control of the router, the highest privilege tier available on RouterOS; a failed or partial trigger could instead crash the management service or the device itself, producing a denial-of-service outage.

Exploitation Status

At the time of publication, CISA said it had received no reports of public exploitation specifically targeting CVE-2026-84411, and researchers tracking the disclosure have not identified a working proof-of-concept in circulation. That is a narrower statement than "not being exploited," however — it reflects what has been reported, not a guarantee of what is happening on exposed devices. Internet-facing network appliances are routinely scanned and probed within hours of a CISA advisory going public, and MikroTik hardware in particular has a well-established history of being targeted quickly once a critical flaw is disclosed.


Impact Assessment

Impact AreaDescription
ConfidentialityRoot access exposes full router configuration, VPN/API credentials, and all traffic transiting the device
IntegrityAn attacker with root code execution can rewrite firewall rules, routing tables, DNS settings, and firmware-level configuration
AvailabilityEven a failed exploitation attempt can crash the web management service or the device, causing outages for dependent networks
ScopeAny internet-reachable RouterOS device earlier than version 7.24 with the web management (HTTP) service enabled
Sector ExposureCISA identifies Communications and Information Technology as the primarily affected critical infrastructure sectors; MikroTik gear is deployed globally by ISPs, MSPs, and enterprises
Compounding RiskArrives in the same month as two other high-severity, actively exploited RouterOS CVEs (CVE-2026-67279, CVE-2026-86060), increasing the odds that unpatched fleets are vulnerable to multiple independent attack paths at once

Recommendations

For Network Administrators

  1. Upgrade immediately to RouterOS 7.24 or later — the latest stable release is 7.24.4 and the latest long-term release is 7.23.7, both available since September 16, 2026. MikroTik had not yet published its own advisory confirming the exact patched build list at the time of initial reporting, so verify the fix is present in your specific release channel before standing down.
  2. Disable the web management (HTTP) interface on any device that doesn't operationally require it, and restrict access to it from a management VLAN or VPN rather than the open internet.
  3. Inventory every RouterOS deployment — including devices managed by downstream customers, if you're an MSP or ISP — and confirm current firmware version across the fleet.

For Security Teams

  1. Treat every internet-facing RouterOS web management endpoint as high-risk until patched, regardless of whether active exploitation has been confirmed for this specific CVE.
  2. Place control-network and management interfaces behind firewalls, separated from general business and customer traffic, per CISA's standing ICS/network-appliance guidance.
  3. Monitor for anomalous behavior on RouterOS devices post-advisory: unexpected reboots, web management service crashes, new administrative accounts, or configuration changes outside a known maintenance window.
  4. Use updated VPNs for any remote administrative access rather than exposing management ports directly, and apply defense-in-depth controls consistent with CISA's broader control-systems recommendations.

For General Users and Small Networks

  1. Check your router's RouterOS version via Winbox or the web interface and update as soon as a fix is confirmed for your model and release channel.
  2. Turn off remote/WAN access to the router's management interface if it isn't explicitly needed.
  3. Change default administrative credentials and disable unused services as a general hardening step alongside patching.

Key Takeaways

  1. CVE-2026-84411 is a critical (CVSS 9.8 / 9.3) pre-authentication integer underflow in MikroTik RouterOS's web management service that enables root-level remote code execution or denial of service via a single crafted HTTP request.
  2. No authentication is required — the vulnerable code path runs before any login check, making every internet-exposed, unpatched device a potential target.
  3. RouterOS versions earlier than 7.24 are affected; MikroTik's latest stable (7.24.4) and long-term (7.23.7) builds address it.
  4. No confirmed active exploitation or public proof-of-concept exists yet, but CISA and researchers caution that the absence of reports is not the same as the absence of scanning or attack activity.
  5. This is a separate flaw from the actively exploited "MikroTrick" SSH chain (CVE-2026-67279 and CVE-2026-86060) CosmicBytez Labs covered earlier this month — it targets the HTTP web management service rather than SSH, and administrators need to patch against both independently.
  6. MikroTik RouterOS has now had three critical, CISA-flagged vulnerabilities disclosed in September 2026 alone, reinforcing that internet-exposed router management interfaces remain one of the highest-value targets for opportunistic and targeted attackers.

Sources