TL;DR
CISA published advisory ICSA-26-272-06 on September 29, 2026, for a critical MikroTik RouterOS vulnerability, CVE-2026-84411. A single crafted HTTP request can give an unauthenticated attacker root code execution. The flaw scores CVSS 9.8.
- CVE: CVE-2026-84411 R
- CVSS: 9.8 (Critical · CVSSv3)
- Impact: CWE-191
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy This MikroTik RouterOS Vulnerability Matters
RouterOS runs on MikroTik routers used worldwide in homes, ISPs, and business networks. CISA lists the affected sectors as communications and information technology. The advisory warns that “successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.”
The timing adds pressure. CERT Polska separately reports that attackers have exploited a different pair of RouterOS flaws, known as MikroTrick, since early September.
How the Attack Works
The bug sits in the RouterOS web management service. Its HTTP request body handling contains an integer underflow that runs before any login check. According to CISA, an attacker can use it “to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.”
Affected Versions and Exploitation Status
CISA lists RouterOS versions before 7.24 as affected. An anonymous researcher reported the flaw. CISA states that “no known public exploitation specifically targeting this vulnerability has been reported.” No public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Update RouterOS from the official MikroTik download page. MikroTik’s latest fixed releases are 7.24.2 and 7.23.4, which also close the MikroTrick flaws.
Until you patch, keep the web management interface off the internet. Limit access to trusted IP ranges or a VPN. Because this MikroTik RouterOS vulnerability needs no credentials, exposed routers should be patched first.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!