Protect.Computer
NEWS

CISA Warns of Critical Pre-Auth RCE in MikroTik RouterOS

· 1 min read · Network safety Device safety
CISA Warns of Critical Pre-Auth RCE in MikroTik RouterOS

CISA has published an advisory about CVE-2026-84411, a critical flaw in the web-management service of MikroTik RouterOS. It is an integer underflow in how the service handles HTTP request bodies, and it can be reached before any login. According to CISA, a single crafted request from an unauthenticated network attacker can produce arbitrary code execution as root, or crash the device.

CISA says it has no knowledge of active exploitation, and MikroTik had not yet published its own advisory when BleepingComputer reported on it. The warning still matters: MikroTik routers are frequent botnet targets, and Poland’s CERT recently warned that attackers chained two other RouterOS flaws (CVE-2026-67276 and CVE-2026-86060) to take over devices with exposed SSH.

How to check if you’re affected

Affected versions are MikroTik RouterOS releases below 7.24, and the vendor recommends moving to 7.23 or later. Log in to the router and run /system resource print (or open System > Resources in WinBox) to see your version, then upgrade through System > Packages. The latest stable release is 7.24.4 and the newest long-term release is 7.23.7. Until you have patched, make sure the web management interface (WebFig, ports 80/443) is not reachable from the internet, and limit access with firewall rules or /ip service address restrictions.

Sources

Related reading