The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of a critical vulnerability in MikroTik RouterOS that could allow remote code execution or cause a denial-of-service condition.
Tracked as CVE-2026-84411, the flaw is an integer underflow in the web-management service’s handling of HTTP request bodies. CISA says an unauthenticated attacker can use a single crafted request to execute code with root privileges or cause a denial of service.
CISA said it has no knowledge of the vulnerability being actively exploited. The agency issued its advisory to alert organizations to the risk and provide defensive measures. It says RouterOS versions below 7.24 are affected, while MikroTik recommends updating to version 7.23 or later to mitigate the risk.
The latest stable RouterOS release is 7.24.4, and the latest long-term release is 7.23.7. Both have been available since September 16. BleepingComputer said it contacted MikroTik and CISA for clarification about the affected versions but had not received a response at publication. MikroTik had not published a security advisory about the issue.
CISA also noted that attackers and botnet malware often target MikroTik flaws. Poland’s CERT agency recently warned that attackers used a chain involving CVE-2026-67276 and CVE-2026-86060 to take control of devices with SSH services exposed to the internet. That report concerns separate vulnerabilities; CISA said it had no knowledge of active exploitation of CVE-2026-84411.
Comments
0No comments yet. Be the first to comment.