Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

MikroTik RouterOS flaw rated 9.8 allows root takeover with no login, CISA warns

An integer underflow in RouterOS's web management service is reachable before login and can give an attacker root access or crash the router, CISA said.

By · Editor

· 2 min read · Fact-checked

The 60-second brief

  • 1CISA says CVE-2026-84411 in MikroTik RouterOS before 7.24 can allow root code execution without authentication.
  • 2The flaw scores 9.8 under CVSS v3.1 and sits in the web management service's HTTP request handling.
  • 3CISA reported no known public exploitation, but attackers have repeatedly hijacked MikroTik routers via other flaws.

The news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of a critical MikroTik RouterOS vulnerability that can let an unauthenticated attacker run code as root on affected routers. CISA published the advisory, ICSA-26-272-06, on September 29, 2026, covering RouterOS versions before 7.24.

The flaw, tracked as CVE-2026-84411, is an integer underflow in how the RouterOS web management service handles the body of HTTP requests, according to CISA. An integer underflow is a math error where a number wraps around to a huge value, which can let an attacker write past the memory a program expected to use.

CISA said the bug is reachable before authentication. Successful exploitation could result in remote code execution as the root user or a denial of service. BleepingComputer, summarizing the alert, reported that a single crafted request can be enough.

CISA rated the flaw 9.8 under CVSS v3.1, describing a network attack of low complexity that needs no privileges or user interaction, and 9.3 under the newer CVSS v4.0. The agency credited an anonymous researcher and listed communications and information technology as affected sectors.

CISA's fix guidance is to update to RouterOS 7.24 or later. BleepingComputer reported that the latest stable release, 7.24.4, and the latest long-term release, 7.23.7, were both available as of September 16; administrators should confirm with MikroTik which long-term build contains the fix. CISA said no known public exploitation specifically targeting this vulnerability had been reported.

The numbers

CVSS v3.1 score
9.8
CVSS v4.0 score
9.3
First fixed version, per CISA
RouterOS 7.24
Advisory released
September 29, 2026

Why CEOs should care

MikroTik routers are popular in branch offices, small businesses and internet service provider networks because they are cheap and flexible. That same reach makes them a favorite target for botnets, networks of hijacked devices that attackers rent out for traffic floods or use to hide their tracks. BleepingComputer noted that attackers recently exploited two other MikroTik flaws to hijack routers with exposed SSH services.

For CISOs and network leaders, the action list is short. Find every MikroTik device you own or that a provider runs for you, confirm its RouterOS version, and schedule updates to 7.24 or later. Most important, make sure the web management interface is not reachable from the internet; CISA's standard guidance is to keep control systems off the open internet, behind firewalls, and reached only over an up-to-date VPN.

For CFOs and boards, the risk is less about the router itself and more about what a compromised router enables: traffic interception at a branch, a pivot into the corporate network, or your company's IP addresses showing up in someone else's attack. Ask whether network gear is in the same patch program as servers and laptops, and who owns it at remote sites.

The bigger picture

Routers and other edge devices are an attractive target because they rarely run endpoint security software and are often patched less often than computers. A pre-authentication flaw, one that works before any login, removes the usual barrier of needing stolen credentials.

CISA publishing a MikroTik issue through its industrial control systems advisory channel reflects how widely these routers are used in operational and communications networks, not just office IT.

What’s next

The key signal to watch is whether CVE-2026-84411 appears in CISA's Known Exploited Vulnerabilities catalog, which would mean confirmed attacks and set deadlines for federal agencies. Until then, organizations have time to update to RouterOS 7.24 or later and lock down management access.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

MikroTikCISARouterOSNetwork security

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.