The CISA agency has warned about the critical vulnerability CVE‑2026‑84411 in MikroTik RouterOS, which allows a remote attacker to execute arbitrary code with root privileges or cause a denial of service using a single specially crafted HTTP request to the web management interface without any authentication; all RouterOS versions below 7.24 are vulnerable, so network administrators must urgently update to 7.24 or newer, or strictly limit access to web management.
Technical details of the CVE‑2026‑84411 vulnerability
According to the official CISA notice ICS advisory for CVE‑2026‑84411, the vulnerability has been assigned a score of 9.8 on the CVSS scale, which corresponds to a critical level. The issue is related to an integer underflow error when processing HTTP requests in the RouterOS web management interface.
Key characteristics of the attack vector:
- exploitation occurs before authentication, i.e., without a login/password or keys;
- a single specially crafted HTTP request to the web interface is sufficient;
- successful exploitation gives the attacker arbitrary code execution with root privileges or leads to denial of service (DoS);
- all RouterOS versions below 7.24 are vulnerable.
The error occurs at the stage of parsing incoming HTTP traffic in the management component, before any access control. In this context, integer underflow means the input data forces a counter or buffer size into the negative range, which is then interpreted as a very large positive number. In practice, this often leads either to writing data outside the permitted range or to reading from “foreign” memory regions.
This combination — pre‑authentication processing of network input plus a memory handling error — is typical for remote code execution vulnerabilities. At the same time, exploitation usually does not require complex multi‑stage logic: it is enough to deliver a correctly crafted request to the device’s web interface.
At the time of publication, CISA specifically emphasizes that there is currently no data on exploitation of CVE‑2026‑84411 “in the wild”. Nonetheless, due to the low exploitation complexity and high criticality, it is reasonable to expect working exploits to appear quickly after sufficient technical details are released. To track formal information about the vulnerability, you can use the NVD page: NVD entry for CVE‑2026‑84411.
An important nuance is the version confusion. Initially, in the CISA advisory it was suggested to update to RouterOS 7.23 or higher while simultaneously stating that all versions below 7.24 were vulnerable. The typo was later corrected. It now states that the issue affects all versions below 7.24, and the recommended version is 7.24 or newer. At the same time, the original material notes:
- the current stable version is 7.24.4;
- the latest long‑term branch version is 7.23.7;
- both were released on 16 September 2026;
- 7.23.7 formally falls into the range of versions “below 7.24” as defined by CISA.
This creates an additional area of uncertainty for owners of the long‑term branch: on the one hand, the version is fresh, on the other hand, by CISA’s wording it is still considered vulnerable.
Threat context: MikroTrick and other bugs in RouterOS
The new CVE‑2026‑84411 vulnerability did not appear in a vacuum. In early September, CERT Polska specialists reported six other vulnerabilities in RouterOS, some of which, according to them, are already being used in attacks. Two of them, CVE‑2026‑67279 and CVE‑2026‑86060, have been grouped under the name MikroTrick; a combination of these two bugs allows a complete takeover of the device if its SSH access is open to the internet. The technical analysis has been published in the CERT Polska report: MikroTrick – technical analysis.
The same report highlights another SSH bug — CVE‑2026‑67276. It was initially mistakenly associated with the MikroTrick attack, but CERT Polska shows that this is a separate issue: it allows an attacker to impersonate a user with an RSA key, provided they know the account name and the modulus of its public key. In other words, this is not a “zero‑day” that can be mass‑exploited against anonymous devices without preparation, but given sufficient context about a specific target, the risk is high.
Formally, these vulnerabilities are independent: MikroTrick is tied to the combination of CVE‑2026‑67279 and CVE‑2026‑86060, while CVE‑2026‑67276 is a standalone SSH flaw. However, from an infrastructure protection standpoint, they form a single picture: the RouterOS attack surface is expanding simultaneously through both the web interface and the SSH subsystem. The presence of the critical CVE‑2026‑84411 in the web component only reinforces the motivation to comprehensively revise management practices for MikroTik devices.
For a complete formal picture of the related vulnerabilities, you can also track them in NVD, for example the NVD entry for CVE‑2026‑67279.
Impact assessment for organizations
All organizations where RouterOS is used as a perimeter or remote network device and the web management interface is accessible from untrusted networks (especially from the internet) are at increased risk. In this configuration, CVE‑2026‑84411 turns any vulnerable router into a convenient entry point.
Potential consequences of successful exploitation can be roughly divided into two levels:
- Full device takeover (remote code execution with root privileges):
- reconfiguring routing and access control lists, creating hidden tunnels;
- spoofing, intercepting, or mirroring traffic passing through the device;
- using the router as a foothold for attacks on internal networks;
- stealthy installation of additional malicious components.
- Denial of service:
- loss of connectivity with branches and remote sites;
- downtime of critical business processes dependent on access to external resources;
- difficulty or complete inability to perform remote administration precisely at a crisis moment.
Scenarios where, for convenience, web management is exposed to the internet “for administrators on the road” are especially vulnerable. Combined with the pre‑authentication nature of CVE‑2026‑84411, this makes such devices priority targets: the attack requires neither credentials nor prior reconnaissance inside the network.
There is a separate operational risk associated with the long‑term branch. Version 7.23.7 is positioned as long‑term and has just been updated, but under CISA’s wording it still formally falls into the vulnerable range. For conservative infrastructures where switching between branches takes months, this creates a dilemma between stability and security.
Practical recommendations for risk reduction
1. RouterOS updating and version management
- Follow CISA’s recommendation and move devices to RouterOS 7.24 and newer, starting with the most critical nodes (perimeter routers, devices with direct internet access).
- Given that 7.23.7 formally falls into the vulnerable version range below 7.24 announced by CISA, long‑term branch owners should at least assess the possibility of a pilot migration of part of the infrastructure to 7.24.4 or subsequent stable releases.
- Before mass updating, perform testing on non‑production devices, but do not drag out the process: with a CVSS of 9.8, the window before mass exploits appear is usually small.
2. Strictly limiting access to management interfaces
CISA directly recommends minimizing exposure of RouterOS management interfaces. In practice, this means:
- blocking direct access to the web management interface from the internet; where possible, completely disable web management on external interfaces;
- restricting access to management (HTTP/HTTPS, SSH, Winbox and other administration protocols) only from dedicated administrative subnets through firewalls;
- separating management networks and remote devices from corporate networks using distinct segments and firewall rules, as recommended by CISA;
- for remote administration, using modern VPN solutions, providing access to management interfaces only after a secure tunnel is established.
3. Response prioritization
To avoid spreading resources too thin, it is worth organizing work on CVE‑2026‑84411 in stages:
- Compile a list of all MikroTik RouterOS devices, including branches, remote sites, and test environments.
- Identify devices whose web management interface is accessible from the internet or other untrusted zones.
- For this group:
- first, restrict access (traffic filtering, disabling web management on external interfaces);
- then update to versions 7.24 and above as quickly as possible.
- At the second stage, update the remaining devices and bring their management configurations in line with unified strict standards (no direct internet access, segmentation, VPN).
4. Combining work on CVE‑2026‑84411 and MikroTrick
If the organization is already responding to the MikroTrick bugs discovered by CERT Polska (CVE‑2026‑67279, CVE‑2026‑86060) and the SSH vulnerability CVE‑2026‑67276, it is reasonable to combine the processes:
- treat all RouterOS devices as a single risk class with the possibility of full takeover under a vulnerable web and SSH configuration;
- simultaneously tighten policies for SSH (minimizing exposure, controlling accounts and keys) and for web management;
- include in prioritization criteria not only the firmware version, but also the fact that web and SSH interfaces are accessible from the internet.
The main practical takeaway: you can minimize the likelihood of CVE‑2026‑84411 exploitation only by combining two steps — urgently closing the RouterOS web management interface from the internet (through filtering and segmentation) and a planned but not protracted update of all devices to versions 7.24 and newer, with particular attention to those routers that serve as perimeter nodes and remote access points.