CISA Warns of Critical Pre-Authentication RCE Flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding a new vulnerability in **MikroTik RouterOS**. Tracked as **CVE-2026-84411**, this pre-authentication integer underflow could enable remote code execution with root privileges or trigger a denial-of-service condition with a single crafted HTTP request.

**CISA** has alerted organizations to a significant security flaw in **MikroTik RouterOS**, a widely used operating system for MikroTik routers. This vulnerability, identified as **CVE-2026-84411**, presents a severe risk due to its pre-authentication nature and potential for unauthenticated remote code execution (RCE).
### Understanding CVE-2026-84411
The vulnerability is an integer underflow located within the web-management HTTP request handling of **RouterOS**. According to CISA, a single maliciously crafted request is sufficient to exploit this flaw, leading to either arbitrary code execution with root privileges or a denial-of-service (DoS) condition.
"The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication," reads the CISA advisory. "This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request."
### Affected Versions and Mitigation
While **CISA** states that **MikroTik RouterOS** versions below 7.24 are currently affected, the agency recommends that users update to version 7.23 or later to mitigate the risk. It's worth noting that the latest stable version of **MikroTik RouterOS** is 7.24.4, and the most recent long-term release is 7.23.7, both available since September 16.
As of publication, neither **MikroTik** nor CISA have provided further clarification on the specific affected versions, and **MikroTik** has yet to publish its own security advisory on the issue.
### CISA's Defensive Recommendations
Despite no active exploitation of **CVE-2026-84411** being publicly disclosed, **CISA** emphasizes the importance of immediate defensive actions for **MikroTik** router owners. These include:
1. **Isolate Control Systems:** Ensure control systems are not directly accessible from the internet.
2. **Network Segmentation:** Place control networks and remote devices behind robust firewalls, isolated from broader business networks.
3. **Secure Remote Access:** Utilize updated Virtual Private Networks (VPNs) for all remote access and secure all connected devices.
### A History of MikroTik Exploits
This new alert comes amidst a backdrop of frequent targeting of **MikroTik** vulnerabilities by attackers and botnet malware. Recently, Polandβs **CERT** agency warned of an exploit chain involving two other **MikroTik RouterOS** vulnerabilities, **CVE-2026-67276** and **CVE-2026-86060**. These flaws were leveraged to gain full control of devices with SSH services exposed to the internet, highlighting the persistent threat landscape for **MikroTik** devices.