The news
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of a critical MikroTik RouterOS vulnerability that can let an unauthenticated attacker run code as root on affected routers. CISA published the advisory, ICSA-26-272-06, on September 29, 2026, covering RouterOS versions before 7.24.
The flaw, tracked as CVE-2026-84411, is an integer underflow in how the RouterOS web management service handles the body of HTTP requests, according to CISA. An integer underflow is a math error where a number wraps around to a huge value, which can let an attacker write past the memory a program expected to use.
CISA said the bug is reachable before authentication. Successful exploitation could result in remote code execution as the root user or a denial of service. BleepingComputer, summarizing the alert, reported that a single crafted request can be enough.
CISA rated the flaw 9.8 under CVSS v3.1, describing a network attack of low complexity that needs no privileges or user interaction, and 9.3 under the newer CVSS v4.0. The agency credited an anonymous researcher and listed communications and information technology as affected sectors.
CISA's fix guidance is to update to RouterOS 7.24 or later. BleepingComputer reported that the latest stable release, 7.24.4, and the latest long-term release, 7.23.7, were both available as of September 16; administrators should confirm with MikroTik which long-term build contains the fix. CISA said no known public exploitation specifically targeting this vulnerability had been reported.
The numbers
- CVSS v3.1 score
- 9.8
- CVSS v4.0 score
- 9.3
- First fixed version, per CISA
- RouterOS 7.24
- Advisory released
- September 29, 2026
Why CEOs should care
MikroTik routers are popular in branch offices, small businesses and internet service provider networks because they are cheap and flexible. That same reach makes them a favorite target for botnets, networks of hijacked devices that attackers rent out for traffic floods or use to hide their tracks. BleepingComputer noted that attackers recently exploited two other MikroTik flaws to hijack routers with exposed SSH services.
For CISOs and network leaders, the action list is short. Find every MikroTik device you own or that a provider runs for you, confirm its RouterOS version, and schedule updates to 7.24 or later. Most important, make sure the web management interface is not reachable from the internet; CISA's standard guidance is to keep control systems off the open internet, behind firewalls, and reached only over an up-to-date VPN.
For CFOs and boards, the risk is less about the router itself and more about what a compromised router enables: traffic interception at a branch, a pivot into the corporate network, or your company's IP addresses showing up in someone else's attack. Ask whether network gear is in the same patch program as servers and laptops, and who owns it at remote sites.
The bigger picture
Routers and other edge devices are an attractive target because they rarely run endpoint security software and are often patched less often than computers. A pre-authentication flaw, one that works before any login, removes the usual barrier of needing stolen credentials.
CISA publishing a MikroTik issue through its industrial control systems advisory channel reflects how widely these routers are used in operational and communications networks, not just office IT.
What’s next
The key signal to watch is whether CVE-2026-84411 appears in CISA's Known Exploited Vulnerabilities catalog, which would mean confirmed attacks and set deadlines for federal agencies. Until then, organizations have time to update to RouterOS 7.24 or later and lock down management access.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







