DKDKCISSPSearch
Vulnerabilities

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

DKCISSP News DeskBleepingComputer30 Sept 2026, 9:19 pm
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

Tracked as CVE-2026-84411, the security issue is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling.

CISA says that a single crafted request can produce code execution with root privileges or denial of service.

Although the agency has no knowledge of the vulnerability being actively exploited, it released the advisory to alert organizations of the risk and to provide defensive measures.

CISA's recommendations to MikroTik router owners include the following defensive actions: Although no active exploitation of CVE-2026-84411 has been publicly disclosed, hackers and botnet malware often target MikroTik flaws.

Recently, Poland’s CERT agency warned that attackers used an exploit chain of two MikroTik RouterOS vulnerabilities, CVE-2026-67276 and CVE-2026-86060 , to take full control of devices with SSH services exposed to the internet.

CISA notes that MikroTik RouterOS versions below 7.24 are currently affected.

However, the agency also says that the vendor recommends that users update to version 7.23 or later to mitigate the risk.

BleepingComputer has emailed both MikroTik and CISA for clarification about the RouterOS versions affected by CVE-2026-84411, but we have not received a response as of publication.

The vendor has yet to publish a security advisory about the issue.

It should be noted that the latest stable version of MikroTik RouterOS is 7.24.4, while the most recent long-term release is 7.23.7, both available since September 16.

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

Tracked as CVE-2026-84411, the security issue is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling.

CISA says that a single crafted request can produce code execution with root privileges or denial of service.

What changed

Although the agency has no knowledge of the vulnerability being actively exploited, it released the advisory to alert organizations of the risk and to provide defensive measures.

CISA's recommendations to MikroTik router owners include the following defensive actions: Although no active exploitation of CVE-2026-84411 has been publicly disclosed, hackers and botnet malware often target MikroTik flaws.

Recently, Poland’s CERT agency warned that attackers used an exploit chain of two MikroTik RouterOS vulnerabilities, CVE-2026-67276 and CVE-2026-86060 , to take full control of devices with SSH services exposed to the internet.

Who is affected

CISA notes that MikroTik RouterOS versions below 7.24 are currently affected.

However, the agency also says that the vendor recommends that users update to version 7.23 or later to mitigate the risk.

Why it matters

BleepingComputer has emailed both MikroTik and CISA for clarification about the RouterOS versions affected by CVE-2026-84411, but we have not received a response as of publication.

The vendor has yet to publish a security advisory about the issue.

Technical details

It should be noted that the latest stable version of MikroTik RouterOS is 7.24.4, while the most recent long-term release is 7.23.7, both available since September 16.

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

Response

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Attribution

BleepingComputer: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmFortinet warns of critical FortiMail flaw exploited in zero-day attacksBleepingComputer · 2 Oct 2026, 4:12 amKiteworks patches max severity code injection vulnerabilityBleepingComputer · 1 Oct 2026, 7:21 pm