Skip to content
Rota Nacional

Cyber ·

Alert: critical MikroTik RouterOS flaw

A CISA-attributed advisory reports a pre-authentication flaw in the RouterOS web service, with risk of remote code execution as root or denial of service. MikroTik recommends upgrading to version 7.23 or later.

The advisory, published on September 29, 2026 and presented as an automatic translation of content from the CISA feed, concerns MikroTik RouterOS. It identifies CVE-2026-84411: an integer underflow in the web management service's handling of HTTP request bodies, reachable before authentication by an unauthenticated network attacker.

According to the summary, a single crafted request may allow remote code execution as root or cause denial of service. The advisory gives the flaw CVSS 3.1 and CVSS 4.0 scores of 9.8 and 9.3, respectively, both critical. It says the product is affected and that MikroTik recommends upgrading to RouterOS 7.23 or later.

To reduce exposure while assessing and applying the fix, identify devices running RouterOS, restrict access to the web management service, and avoid exposing control devices directly to the internet. The advisory also recommends firewalls, separating control networks from business networks, and, when remote access is necessary, an up-to-date VPN. It cautions that VPNs and devices connected to them can also be vulnerable.

Consult the original CISA advisory using identifier ICSA-26-272-06, and check CVE details and upgrade instructions through official CISA and MikroTik channels. Assess operational impact and risk before deploying defensive measures. If using AI to summarize or apply the advisory, provide only the material needed and protect internal information according to your organization's rules.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free