A critical flaw in MikroTik RouterOS lets an attacker who can reach the router's web management service run code as root without logging in, according to an advisory CISA published on September 29. The bug, tracked as CVE-2026-84411, carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, and CISA says a single crafted request is enough to either take over the device or knock it offline.
RouterOS runs on MikroTik's routers and switches, which CISA notes are deployed worldwide, with the communications and IT sectors named in its advisory. The flaw was reported to CISA by an anonymous researcher.
A bug in the front door, before any password
CISA describes the issue as an integer underflow in the way the web management service handles the body of an HTTP request. In plain terms, a number in the request handling code can wrap around past its lower limit. CISA says this one is reachable before authentication and can be used by an unauthenticated network attacker to achieve arbitrary code execution as root. The advisory does not publish further technical detail, and MikroTik's own release notes are the place to look for it.
This is a different problem from the one that dominated MikroTik news earlier in September. That was an SSH weakness that attackers were actively using to seize routers, and one that CERT Polska showed could be reverse engineered from MikroTik's patch within a day. That precedent is the reason not to wait on this one.
No attacks reported, yet
CISA states that no known public exploitation of CVE-2026-84411 has been reported to it at this time. That is a snapshot, not a guarantee. The September SSH episode showed how quickly a published fix can be turned into a working attack.
Upgrade to RouterOS 7.24, and close the web interface
CISA lists every RouterOS release below 7.24 as affected. Its remediation line, quoting MikroTik, tells users to update to "version 7.23 or later", which does not sit neatly with that affected range. Until MikroTik clarifies, 7.24 or newer is the release that falls outside the range CISA marks as vulnerable. Updates are available from MikroTik's download page.
Where an immediate upgrade is not possible, CISA's standard guidance applies directly here: do not expose device management to the internet, keep management interfaces behind a firewall and separate from business networks, and reach them only through a secured, up-to-date VPN. For RouterOS that means restricting which addresses can reach the web management service, or turning it off on internet-facing interfaces if you manage the device another way.
Administrators who patched for the SSH flaw earlier this month should not assume they are covered. Check the running version on every device, not just the ones you touched last time, because a router that was safe two weeks ago can still be one request away from belonging to someone else.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.