securityonline.info 29 Sept 2026, 20:10 UTC

CISA Warns of Critical Unauthenticated RCE in MikroTik RouterOS

CISA Warns of Critical Unauthenticated RCE in MikroTik RouterOS
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISA has issued advisory ICSA-26-272-06 on 29 September 2026 regarding a critical vulnerability in MikroTik RouterOS, CVE-2026-84411. The flaw is an unauthenticated root remote code execution (RCE) exposed by an integer underflow in the HTTP request body handling of the RouterOS web management service. A single crafted HTTP request could allow an unauthenticated attacker to execute code as root or cause a denial of service, with the vulnerability scoring CVSS 9.8.

RouterOS versions affected are listed as prior to 7.24. Evidence in the report notes that an anonymous researcher brought the flaw to light and that there are no publicly known exploitations specific to this vulnerability, nor any public proof-of-concept confirmed at this time. The advisory also references separate activity suggesting attackers have already exploited other RouterOS flaws (MikroTrick) since early September. MikroTik has released fixed releases for the vulnerability: 7.24.2 and 7.23.4, which also address the MikroTrick flaws.

Mitigation steps emphasise updating RouterOS from MikroTik’s official download page and, in the meantime, isolating the web management interface from the internet. Practical guidance includes restricting access to trusted IP ranges or via a VPN, with priority patching for exposed routers since the flaw does not require credentials to exploit.

View full article

Article by CyberSIXT