CISA warns of RouterOS flaw that can let a single request run code as root
MikroTik users exposing router management services need to treat this as a high-priority fix and keep those systems off the public internet.
CISA has warned that a newly disclosed MikroTik RouterOS flaw can let an unauthenticated network attacker run code as root or crash the device with one crafted request, making it a high-priority fix for anyone exposing router management services. The issue is tracked as CVE-2026-84411 and sits in the web-management HTTP request path as an integer underflow. CISA says RouterOS releases below 7.24 are affected, while MikroTik’s mitigation guidance points users to 7.23 or later. The agency says it has no evidence of active exploitation yet, but recommends keeping control systems off the internet, isolating management networks, and using updated VPNs for remote access.
Why it matters
The risk is not limited to a crash: a network attacker can potentially take root on affected RouterOS devices with one crafted request. That makes internet-facing management paths especially sensitive, while CISA’s advice to isolate systems behind firewalls and VPNs points to reducing exposure until patched.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- Tom's Hardware
- BleepingComputer