# CISA warns RouterOS flaw can give attackers root access with one request

_Published Wednesday, September 30, 2026 at 6:20 PM EDT · Security · Latest · Tier 2 — Notable_

![CISA warns RouterOS flaw can give attackers root access with one request — Primary](https://www.bleepstatic.com/content/hl-images/2026/09/07/mikrotik.jpg)

CISA warned that a MikroTik RouterOS vulnerability can allow an unauthenticated attacker to execute code with root privileges or disrupt service using one crafted request, BleepingComputer reported. CVE-2026-84411 involves an integer underflow in the web-management service's handling of HTTP request bodies.

CISA has no knowledge of active exploitation. Its version guidance is inconsistent: it identifies versions below 7.24 as affected but cites a vendor recommendation to update to 7.23 or later. BleepingComputer sought clarification from CISA and MikroTik. CISA also recommends keeping control systems off the internet and isolating them behind firewalls.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/)

---
Canonical: https://techandbusiness.org/newswire/IBXfYOA1vWHgRHNJHX-Sio
Published: 2026-09-30T22:20:48.793Z
Story chronology: 2026-09-30T15:49:29.000Z
Retrieved: 2026-10-01T00:25:22.136Z
Publisher: Tech & Business (techandbusiness.org)
