CISA has issued an advisory for a critical, pre-authentication vulnerability in MikroTik RouterOS that can hand an attacker root-level code execution or take a device offline — no login required.
What happened
Tracked as CVE-2026-84411, the flaw is an integer underflow in how RouterOS's web-management service parses HTTP request bodies. Because the vulnerable code path is reachable before authentication, a single crafted request is enough to trigger arbitrary code execution as root or force a denial-of-service condition.
CISA says it has no evidence of active exploitation so far, but published the advisory to get ahead of it. RouterOS versions below 7.24 are affected. MikroTik has not yet published its own security advisory; CISA's interim guidance is to move to 7.23 or later. The current stable release is 7.24.4, and the latest long-term branch is 7.23.7 — both shipped September 16.
Why it matters
MikroTik routers are a perennial target: botnet operators and opportunistic attackers have a long track record of chaining RouterOS bugs to seize devices at scale. That pattern is already playing out elsewhere — Poland's national CERT recently reported an active exploit chain combining two other RouterOS vulnerabilities to fully compromise routers with SSH exposed to the internet.
A pre-auth, root-level RCE in a device class this widely deployed — and this often left internet-facing — is exactly the kind of bug that turns into mass exploitation once a public proof-of-concept surfaces.
What to do
- Update affected RouterOS devices to 7.23 or later as soon as possible.
- Take web-management and other control interfaces off the public internet — they should never be directly reachable.
- Put remote-management access behind a firewall and a VPN instead of exposing it directly.
- Audit your internet-facing MikroTik devices now, and prioritize any still running SSH or web-management exposed externally — those are the ones attackers will find first.
