CISA Flags Third Critical MikroTik RouterOS Bug This Month
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS, tracked as CVE-2026-84411, that could let an unauthenticated attacker achieve remote code execution as root or trigger a denial-of-service condition. The flaw carries a CVSS v3.1 score of 9.8 (Critical) and a CVSS v4.0 score of 9.3 (Critical), and requires only a single, specially crafted HTTP request against an exposed RouterOS device — no login, credentials, or user interaction needed. CISA published the advisory, tracked as ICSA-26-272-06, on September 29, 2026, after an anonymous researcher reported the bug directly to the agency. It affects RouterOS builds earlier than 7.24, the same month CISA has already logged two other actively exploited MikroTik flaws — CVE-2026-67279 and CVE-2026-86060 — underscoring how heavily RouterOS-based infrastructure is being scrutinized right now.
Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-84411 |
| CISA Advisory | ICSA-26-272-06 |
| Advisory Published | September 29, 2026 |
| CVSS v3.1 Score | 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS v4.0 Score | 9.3 (Critical) |
| CWE Classification | CWE-191 — Integer Underflow (Wrap or Wraparound) |
| Vendor / Product | MikroTik RouterOS |
| Affected Versions | RouterOS builds earlier than 7.24 |
| Component | Web management (HTTP) service |
| Authentication Required | None — reachable pre-authentication |
| Attack Vector | Network, single crafted HTTP request |
| Reported By | Anonymous researcher (via CISA) |
| KEV Status | Not listed in CISA's Known Exploited Vulnerabilities catalog at time of publication |
| Known Exploitation | None confirmed; no public proof-of-concept identified |
| Patched In | RouterOS 7.24 and later (latest builds: stable 7.24.4, long-term 7.23.7, both available since September 16, 2026) |
How It Works
Root Cause
CVE-2026-84411 lives in RouterOS's web management service — the HTTP-based interface (Webfig) that administrators use for browser-based device configuration. According to CISA, the service contains an integer underflow in how it parses the body of incoming HTTP requests, and critically, that parsing logic runs before the service checks whether the requester is authenticated. An integer underflow occurs when an arithmetic operation produces a value below the minimum representable by its integer type, causing the value to wrap around to an unexpectedly large number — a class of bug (CWE-191) that frequently leads to out-of-bounds memory access, buffer miscalculation, or corrupted control-flow state once the wrapped value is used to size or index a buffer.
Exploitation Path
Because the flawed arithmetic executes ahead of any login check, an attacker needs no valid credentials, session token, or prior foothold on the device. CISA's advisory states the bug "can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service" — using a single crafted HTTP request sent to the exposed web management port. Successful exploitation for code execution would hand the attacker root-level control of the router, the highest privilege tier available on RouterOS; a failed or partial trigger could instead crash the management service or the device itself, producing a denial-of-service outage.
Exploitation Status
At the time of publication, CISA said it had received no reports of public exploitation specifically targeting CVE-2026-84411, and researchers tracking the disclosure have not identified a working proof-of-concept in circulation. That is a narrower statement than "not being exploited," however — it reflects what has been reported, not a guarantee of what is happening on exposed devices. Internet-facing network appliances are routinely scanned and probed within hours of a CISA advisory going public, and MikroTik hardware in particular has a well-established history of being targeted quickly once a critical flaw is disclosed.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Root access exposes full router configuration, VPN/API credentials, and all traffic transiting the device |
| Integrity | An attacker with root code execution can rewrite firewall rules, routing tables, DNS settings, and firmware-level configuration |
| Availability | Even a failed exploitation attempt can crash the web management service or the device, causing outages for dependent networks |
| Scope | Any internet-reachable RouterOS device earlier than version 7.24 with the web management (HTTP) service enabled |
| Sector Exposure | CISA identifies Communications and Information Technology as the primarily affected critical infrastructure sectors; MikroTik gear is deployed globally by ISPs, MSPs, and enterprises |
| Compounding Risk | Arrives in the same month as two other high-severity, actively exploited RouterOS CVEs (CVE-2026-67279, CVE-2026-86060), increasing the odds that unpatched fleets are vulnerable to multiple independent attack paths at once |
Recommendations
For Network Administrators
- Upgrade immediately to RouterOS 7.24 or later — the latest stable release is 7.24.4 and the latest long-term release is 7.23.7, both available since September 16, 2026. MikroTik had not yet published its own advisory confirming the exact patched build list at the time of initial reporting, so verify the fix is present in your specific release channel before standing down.
- Disable the web management (HTTP) interface on any device that doesn't operationally require it, and restrict access to it from a management VLAN or VPN rather than the open internet.
- Inventory every RouterOS deployment — including devices managed by downstream customers, if you're an MSP or ISP — and confirm current firmware version across the fleet.
For Security Teams
- Treat every internet-facing RouterOS web management endpoint as high-risk until patched, regardless of whether active exploitation has been confirmed for this specific CVE.
- Place control-network and management interfaces behind firewalls, separated from general business and customer traffic, per CISA's standing ICS/network-appliance guidance.
- Monitor for anomalous behavior on RouterOS devices post-advisory: unexpected reboots, web management service crashes, new administrative accounts, or configuration changes outside a known maintenance window.
- Use updated VPNs for any remote administrative access rather than exposing management ports directly, and apply defense-in-depth controls consistent with CISA's broader control-systems recommendations.
For General Users and Small Networks
- Check your router's RouterOS version via Winbox or the web interface and update as soon as a fix is confirmed for your model and release channel.
- Turn off remote/WAN access to the router's management interface if it isn't explicitly needed.
- Change default administrative credentials and disable unused services as a general hardening step alongside patching.
Key Takeaways
- CVE-2026-84411 is a critical (CVSS 9.8 / 9.3) pre-authentication integer underflow in MikroTik RouterOS's web management service that enables root-level remote code execution or denial of service via a single crafted HTTP request.
- No authentication is required — the vulnerable code path runs before any login check, making every internet-exposed, unpatched device a potential target.
- RouterOS versions earlier than 7.24 are affected; MikroTik's latest stable (7.24.4) and long-term (7.23.7) builds address it.
- No confirmed active exploitation or public proof-of-concept exists yet, but CISA and researchers caution that the absence of reports is not the same as the absence of scanning or attack activity.
- This is a separate flaw from the actively exploited "MikroTrick" SSH chain (CVE-2026-67279 and CVE-2026-86060) CosmicBytez Labs covered earlier this month — it targets the HTTP web management service rather than SSH, and administrators need to patch against both independently.
- MikroTik RouterOS has now had three critical, CISA-flagged vulnerabilities disclosed in September 2026 alone, reinforcing that internet-exposed router management interfaces remain one of the highest-value targets for opportunistic and targeted attackers.