The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical pre-authentication remote code execution (RCE) vulnerability affecting MikroTik RouterOS. The flaw, identified as CVE-2026-84411, is an integer underflow within the web-management HTTP request handling component of RouterOS.
According to CISA, a single specially crafted HTTP request can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution with root privileges or to trigger a denial-of-service condition. This vulnerability exists in the web management service before authentication is required.
CISA's advisory indicates that MikroTik RouterOS versions below 7.24 are susceptible to this vulnerability. However, the agency also noted that the vendor advises users to update to version 7.23 or later to mitigate the risk. The latest stable version of RouterOS is 7.24.4, and the most recent long-term release is 7.23.7, both of which became available on September 16. MikroTik has not yet published its own security advisory concerning CVE-2026-84411.
While CISA has not confirmed active exploitation of CVE-2026-84411, the agency released the advisory to alert organizations to the potential risk and to recommend defensive measures. MikroTik routers are frequently targeted by threat actors and botnet malware. For instance, CERT Polska recently reported that attackers exploited a chain of two other MikroTik RouterOS vulnerabilities, CVE-2026-67276 and CVE-2026-86060, to gain full control over devices with SSH services exposed to the internet.
CISA's recommendations for MikroTik router owners include ensuring that control systems are not accessible from the internet. It is also advised to place control networks and remote devices behind firewalls, isolating them from business networks. Furthermore, CISA recommends using updated virtual private networks (VPNs) for remote access and securing all connected devices.






