Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Andy Burnham’s social care plans could be much more radical | Labour

    September 30, 2026

    Children’s hairpiece charity Locks of Love isn’t a scam. Here’s how we know

    September 30, 2026

    Appeals court halts execution of Tennessee woman less than two hours before lethal injection

    September 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Andy Burnham’s social care plans could be much more radical | Labour
    • Children’s hairpiece charity Locks of Love isn’t a scam. Here’s how we know
    • Appeals court halts execution of Tennessee woman less than two hours before lethal injection
    • Das Anti-Euro-Dilemma – POLITICO
    • Electoral reform could be a gamble too far for Burnham – but so far he’s on a winning streak | Zoe Williams
    • Macron says ‘welcome back’ to Burnham suggestion UK could rejoin EU | European Union
    • Monetary policy in a world of overlapping shocks
    • A Biotech Founder Makes the Moral Case for Gene-Editing Human Embryos
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 30, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.

    Tracked as CVE-2026-84411, the security issue is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling.

    CISA says that a single crafted request can produce code execution with root privileges or denial of service.

    “The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication,” reads the alert.

    “This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.”

    Although the agency has no knowledge of the vulnerability being actively exploited, it released the advisory to alert organizations of the risk and to provide defensive measures.

    CISA notes that MikroTik RouterOS versions below 7.24 are currently affected. However, the agency also says that the vendor recommends that users update to version 7.23 or later to mitigate the risk.

    It should be noted that the latest stable version of MikroTik RouterOS is 7.24.4, while the most recent long-term release is 7.23.7, both available since September 16.

    BleepingComputer has emailed both MikroTik and CISA for clarification about the RouterOS versions affected by CVE-2026-84411, but we have not received a response as of publication. The vendor has yet to publish a security advisory about the issue.

    CISA’s recommendations to MikroTik router owners include the following defensive actions:

    1. Keep control systems inaccessible from the internet.
    2. Place control networks and remote devices behind firewalls, isolated from business networks.
    3. Use updated VPNs for remote access and secure all connected devices.

    Although no active exploitation of CVE-2026-84411 has been publicly disclosed, hackers and botnet malware often target MikroTik flaws.

    Recently, Poland’s CERT agency warned that attackers used an exploit chain of two MikroTik RouterOS vulnerabilities, CVE-2026-67276 and CVE-2026-86060, to take full control of devices with SSH services exposed to the internet.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    CISA critical Flaw MikroTik PreAuth RCE RouterOS warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The MFA you have isn’t the MFA you think you have

    Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    TeamViewer urges users to patch severe flaws “as soon as possible”

    AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

    Bitget hacked via zero-day in third-party security products

    ShinyHunters Defiant After FBI Calls on Members to Come Forward

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Andy Burnham’s social care plans could be much more radical | Labour

    September 30, 2026

    Children’s hairpiece charity Locks of Love isn’t a scam. Here’s how we know

    September 30, 2026

    Appeals court halts execution of Tennessee woman less than two hours before lethal injection

    September 30, 2026

    Das Anti-Euro-Dilemma – POLITICO

    September 30, 2026
    Latest Posts

    Don Lemon Accuses Justice Dept. of Vindictive Prosecution in Church Protest Case

    August 7, 2026

    Kemi Badenoch pens letter to Clacton voters ahead of by-election

    August 7, 2026

    Thetford residents remain on edge after days of ‘mob rule’ over asylum plans | Norfolk

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Andy Burnham’s social care plans could be much more radical | Labour

    September 30, 2026

    Children’s hairpiece charity Locks of Love isn’t a scam. Here’s how we know

    September 30, 2026

    Appeals court halts execution of Tennessee woman less than two hours before lethal injection

    September 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.