MikroTik RouterOS CVE-2026-84411 enables pre-auth root RCE

MikroTik RouterOS CVE-2026-84411 enables pre-auth root RCE

A critical flaw in MikroTik RouterOS can let an attacker take over a router without logging in, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). CISA is the federal agency responsible for coordinating cyber defense for U.S. government networks and critical infrastructure.

The vulnerability, tracked as CVE-2026-84411, sits in the part of RouterOS that handles HTTP requests sent to the web management interface. It is an integer underflow, and it can be triggered before any authentication takes place.

One request is enough

An integer underflow happens when a calculation produces a number smaller than the variable can hold, so the value wraps around to something unexpected. In this case, the bug affects how RouterOS processes the body of incoming HTTP requests.

CISA says that one specially crafted request is enough to exploit it. Depending on how the attack is carried out, the result is either code execution with root privileges or a denial-of-service condition.

"The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication," the agency wrote in its alert.

"This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request."

Root access on a router gives an attacker full control of the device. That includes the traffic passing through it and the rest of the network behind it.

No known exploitation yet

CISA says it is not aware of attacks exploiting CVE-2026-84411. The agency published the advisory to warn organizations about the risk and to share defensive measures before that changes.

MikroTik has not published its own security advisory on the issue so far.

Confusion over affected versions

The version information in the alert does not fully add up. CISA lists RouterOS versions below 7.24 as affected. The same advisory also says MikroTik recommends updating to version 7.23 or later to reduce the risk.

That leaves open whether the 7.23 branch is actually safe. BleepingComputer contacted both MikroTik and CISA for clarification but had not received a reply at the time of its report.

For reference, the current stable RouterOS release is 7.24.4 and the current long-term release is 7.23.7. Both have been available since September 16. Admins who want to stay on the safe side may prefer the stable 7.24.x branch until the vendor confirms which versions are fixed.

CISA's advice

Alongside the update guidance, CISA recommends several general hardening steps for MikroTik router owners:

  • keep control systems unreachable from the internet
  • put control networks and remote devices behind firewalls and separate them from business networks
  • use up-to-date VPNs for remote access and secure every connected device

For CVE-2026-84411 specifically, the most important point is that the vulnerable code sits in the web management service. Routers whose management interface can be reached from the internet are the most exposed.

A popular target

MikroTik devices have long attracted cybercriminals and botnet operators, and flaws in RouterOS tend to get attention quickly.

Only recently, Poland's CERT agency reported that attackers had chained two other RouterOS vulnerabilities, CVE-2026-67276 and CVE-2026-86060, to gain full control of devices that exposed their SSH service to the internet.

Why It Matters

For readers who run MikroTik hardware, this is a patch-now situation, even without confirmed attacks. A bug that needs no credentials and only one request is about as simple as exploitation gets. It is the kind of flaw that tends to end up in scanning tools and botnets once technical details become public.

The advisory also fits a wider pattern of attacks on network edge devices. In recent weeks we have covered a critical WatchGuard Fireware OS flaw, an exploited Check Point VPN bug and ongoing mass exploitation of Citrix NetScaler appliances. Routers, firewalls and VPN gateways face the internet, often run without endpoint monitoring and give access to everything behind them. That makes them attractive entry points.

The unclear version guidance is a real problem. Until MikroTik publishes its own advisory, admins cannot be sure a long-term 7.23.x install is protected. It is worth watching whether the vendor confirms the fixed builds, whether a proof-of-concept appears, and whether CISA later adds the flaw to its list of actively exploited vulnerabilities. In the meantime, taking the web management interface off the internet is a sensible step on its own.