A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute arbitrary code with root-level privileges or trigger a denial-of-service condition.

The flaw, tracked as CVE-2026-84411, affects MikroTik RouterOS versions before 7.24 and has a CVSS v3 severity score of 9.8. The U.S. Cybersecurity and Infrastructure Security Agency published the advisory, identified as ICSA-26-272-06, on September 29, 2026.

The vulnerability affects networking devices deployed globally, including systems used across communications and information technology environments.

CVE-2026-84411 is classified as an integer underflow, also known as an integer wraparound issue. This type of weakness occurs when software performs a calculation that produces a value below the minimum limit supported by the relevant data type.

Instead of safely rejecting the invalid value, the application may wrap it into an unexpectedly large number. In a network-facing product such as RouterOS, an attacker may send specially crafted requests designed to trigger the vulnerable code path.

Critical MikroTik RouterOS Flaw

Successful exploitation could enable remote code execution, potentially giving an attacker root-level control of the affected router. Root access would provide broad control over device settings, traffic handling, routing configurations, authentication services, firewall rules, and installed scripts.

Compromise of an internet-exposed RouterOS device can create serious downstream risks. Attackers could use a compromised router to intercept or redirect network traffic, deploy malware, modify DNS settings, establish persistent access, scan internal systems, or use the device as an entry point into a wider enterprise environment.

In industrial environments, the impact may be more severe where routers provide connectivity to remote sites, operational technology networks, or control system assets.

CISA warned that exploitation could also cause a denial-of-service condition. This could disrupt routing services and make remote devices or connected business systems unavailable.

Organizations relying on MikroTik devices for branch connectivity, remote administration, internet edge routing, or industrial communications should assess exposure immediately.

The primary mitigation is to upgrade affected MikroTik RouterOS installations to version 7.24 or later. Organizations should identify all MikroTik devices in their environment, including systems managed by regional offices, third-party providers, and remote operational sites.

Asset inventories should also account for routers that are not centrally managed or are deployed in legacy network segments. Administrators should restrict management interfaces so they are not directly reachable from the public internet.

CISA recommends minimizing network exposure for control system devices, placing remote assets behind firewalls, and separating operational technology networks from business systems.

Where remote access is required, organizations should use secure, fully updated VPN services and protect VPN access with strong authentication and device security controls.

Network teams should review RouterOS logs for unexpected administrative activity, configuration changes, unusual outbound traffic, new scripts, altered DNS settings, and unknown user accounts. They should also rotate exposed credentials after patching and validate firewall and access-control configurations.

CISA said it has not received reports of public exploitation specifically targeting CVE-2026-84411. However, the combination of unauthenticated access, potential root-level code execution, and widespread RouterOS deployment makes prompt remediation essential.