A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a denial-of-service condition.
This vulnerability, tracked as CVE-2026-84411, affects MikroTik RouterOS versions earlier than 7.24 and carries a CVSS v3 severity score of 9.8.
The Cybersecurity and Infrastructure Security Agency (CISA) disclosed this issue on September 29, 2026, in advisory ICSA-26-272-06.
The agency warned that successful exploitation could let a threat actor run arbitrary code remotely, potentially leading to full device compromise, network pivoting, traffic interception, or persistent access to environments that rely on affected routers.
MikroTik RouterOS Vulnerability
The vulnerability is classified as an integer underflow, also known as an integer wraparound. This type of flaw occurs when a software component performs arithmetic that produces a value below the minimum representable by its integer type.
Instead of safely rejecting this invalid value, the application may wrap it to a very large positive number. In security-sensitive code, this can result in faulty memory allocation, improper bounds validation, unexpected processing paths, or memory corruption.
Depending on the vulnerable RouterOS component and how an attacker exploits it, this issue could lead to remote code execution or service disruption.
MikroTik routers are widely deployed across enterprise, service-provider, small-business, and industrial environments. CISA identifies communications and information technology as affected critical infrastructure sectors and notes that the vulnerable products are used worldwide.
Affected Product
| Vendor | Product | Affected versions | Vulnerability | Severity |
|---|---|---|---|---|
| MikroTik | RouterOS | Earlier than 7.24 | CVE-2026-84411 | CVSS 9.8 Critical |
An anonymous researcher reported the vulnerability to CISA. At the time of publication, CISA stated it had received no reports of public exploitation specifically targeting CVE-2026-84411.
However, the absence of confirmed exploitation should not be interpreted as a low-risk condition. Internet-facing network appliances are routinely scanned after vulnerability disclosures, and a critical RouterOS flaw may quickly become a target for opportunistic actors, botnet operators, initial-access brokers, and ransomware affiliates.
Organizations using MikroTik RouterOS should immediately identify exposed devices and upgrade affected systems to RouterOS version 7.24 or later, following internal change management and impact assessment procedures.
Security teams should prioritize devices that have internet-exposed management services, remote administration enabled, or privileged access to industrial, enterprise, and telecommunications networks.
Organizations that detect suspicious activity should preserve relevant logs and follow incident-response procedures, including reporting findings to CISA for correlation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

