MikroTik RouterOS critical flaw CVE-2026-84411 allows unauthenticated root code execution: update to 7.24
EditorialBy TrustList Editorial
Italy’s national cyber agency warns of a critical flaw in MikroTik RouterOS before 7.24 that lets an unauthenticated remote attacker run code as root or knock the device offline. No exploitation reported. Update routers and switches to 7.24.
- Cybersecurity
- Network Security
- Vulnerability Management
- Patch Management
About MikroTik RouterOS critical flaw CVE-2026-84411 allows unauthenticated root code execution: update to 7.24
MikroTik RouterOS critical flaw CVE-2026-84411 allows unauthenticated root code execution: update to 7.24
1 October 2026 — MikroTik routers and switches running RouterOS before version 7.24 have a critical vulnerability, CVE-2026-84411. Italy's national cybersecurity agency (ACN), through CSIRT Italia, published an alert on 1 October 2026. It says the flaw could let an unauthenticated remote attacker run arbitrary code with root privileges, or make the device unavailable. CSIRT Italia rates its systemic impact as high and recommends updating in line with the vendor's guidance.
Not yet independently verified. This rests on CSIRT Italia’s alert, which cites a US CISA industrial-control-systems advisory that refused our reader. MikroTik’s own changelog does not name the CVE, so the fixed version is as CSIRT Italia states it. No exploitation or public proof-of-concept is reported. BleepingComputer reported the CISA advisory on 30 September. We will update this when it can be confirmed, and remove this note.
What is affected
- Product: MikroTik RouterOS, the operating system of MikroTik's routers, switches and wireless equipment.
- Versions: all before 7.24.
- Impact: remote code execution as root, or denial of service, without authentication.
- Exploitation: none reported by CSIRT Italia, which lists no proof-of-concept and no exploitation.
Why it matters
MikroTik equipment is cheap, capable and everywhere: small offices, branch sites, internet service providers, hotels and industrial sites. It has been a favourite target for botnets for years, because many devices sit directly on the internet with their management services exposed and are rarely updated. We wrote about a different RouterOS flaw, CVE-2026-67279, on 26 September. An unauthenticated root-level flaw is the kind that gets weaponised quickly once details are public.
What to do
- Update RouterOS to 7.24 or later on every MikroTik device, including the ones nobody remembers: branch routers, test units and devices managed by a provider.
- Close management access from the internet: Winbox, the web interface, SSH and the API should be reachable only from trusted networks or a VPN.
- Check for unexpected changes to users, scripts, scheduled tasks and firewall rules on devices that were exposed.
- Ask your internet or managed-network provider whether customer-premises MikroTik equipment has been updated.
Sources
Categories & features
- Cybersecurity
- Network Security
- Vulnerability Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.