CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

A Critical Flaw in MikroTik RouterOS Leaves Devices Vulnerable to Remote Code Execution and Denial-of-Service Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a vulnerability in MikroTik RouterOS that could allow an attacker to execute code remotely or cause a denial-of-service condition on affected devices. The flaw, tracked as CVE-2026-84411, is a pre-authentication integer underflow in the web-management HTTP request handling of RouterOS.

This means that an unauthenticated network attacker can send a single crafted request to the device’s web management service, leading to arbitrary code execution with root privileges or denial-of-service. While CISA has no knowledge of active exploitation at this time, it released the advisory to alert organizations of the risk and provide defensive measures to mitigate the vulnerability.

The affected RouterOS versions are those below 7.24. However, MikroTik recommends updating to version 7.23 or later as a precautionary measure. The latest stable version of RouterOS is 7.24.4, while the most recent long-term release is 7.23.7, both available since September 16.

It’s worth noting that CISA has provided recommendations for MikroTik router owners to take defensive actions against this vulnerability. These include keeping control systems inaccessible from the internet, placing control networks behind firewalls and isolated from business networks, using updated VPNs for remote access, and securing all connected devices.

This advisory comes at a time when hackers and botnet malware have been targeting MikroTik flaws in recent attacks. In July, Poland’s CERT agency warned of an exploit chain targeting two vulnerabilities (CVE-2026-67276 and CVE-2026-86060) to take full control of devices with SSH services exposed to the internet.

The CISA advisory serves as a reminder that even seemingly secure systems can be vulnerable to critical flaws. RouterOS users should prioritize updating their software to the latest version, implement robust security measures, and keep their networks isolated from the public internet to minimize the risk of exploitation.

To stay ahead of potential threats, it’s essential for organizations and individuals alike to regularly monitor their network for signs of unusual activity, patch vulnerabilities promptly, and maintain up-to-date antivirus protection. By taking these proactive steps, you can significantly reduce your exposure to cyber threats and keep your systems secure in today’s ever-evolving threat landscape.

In conclusion, the critical flaw in MikroTik RouterOS highlights the ongoing need for vigilance and proactive security measures in the face of emerging threats. We urge all affected users to prioritize updating their software and implementing robust security protocols to minimize the risk of exploitation.


Source: Bleeping Computer — 2026-09-30