Skip to content
TrustList
News

MikroTik RouterOS critical flaw CVE-2026-84411 allows unauthenticated root code execution: update to 7.24

Editorial

By TrustList Editorial

Italy’s national cyber agency warns of a critical flaw in MikroTik RouterOS before 7.24 that lets an unauthenticated remote attacker run code as root or knock the device offline. No exploitation reported. Update routers and switches to 7.24.

  • Cybersecurity
  • Network Security
  • Vulnerability Management
  • Patch Management

About MikroTik RouterOS critical flaw CVE-2026-84411 allows unauthenticated root code execution: update to 7.24

MikroTik RouterOS critical flaw CVE-2026-84411 allows unauthenticated root code execution: update to 7.24

1 October 2026 — MikroTik routers and switches running RouterOS before version 7.24 have a critical vulnerability, CVE-2026-84411. Italy's national cybersecurity agency (ACN), through CSIRT Italia, published an alert on 1 October 2026. It says the flaw could let an unauthenticated remote attacker run arbitrary code with root privileges, or make the device unavailable. CSIRT Italia rates its systemic impact as high and recommends updating in line with the vendor's guidance.

Not yet independently verified. This rests on CSIRT Italia’s alert, which cites a US CISA industrial-control-systems advisory that refused our reader. MikroTik’s own changelog does not name the CVE, so the fixed version is as CSIRT Italia states it. No exploitation or public proof-of-concept is reported. BleepingComputer reported the CISA advisory on 30 September. We will update this when it can be confirmed, and remove this note.

What is affected

  • Product: MikroTik RouterOS, the operating system of MikroTik's routers, switches and wireless equipment.
  • Versions: all before 7.24.
  • Impact: remote code execution as root, or denial of service, without authentication.
  • Exploitation: none reported by CSIRT Italia, which lists no proof-of-concept and no exploitation.

Why it matters

MikroTik equipment is cheap, capable and everywhere: small offices, branch sites, internet service providers, hotels and industrial sites. It has been a favourite target for botnets for years, because many devices sit directly on the internet with their management services exposed and are rarely updated. We wrote about a different RouterOS flaw, CVE-2026-67279, on 26 September. An unauthenticated root-level flaw is the kind that gets weaponised quickly once details are public.

What to do

  • Update RouterOS to 7.24 or later on every MikroTik device, including the ones nobody remembers: branch routers, test units and devices managed by a provider.
  • Close management access from the internet: Winbox, the web interface, SSH and the API should be reachable only from trusted networks or a VPN.
  • Check for unexpected changes to users, scripts, scheduled tasks and firewall rules on devices that were exposed.
  • Ask your internet or managed-network provider whether customer-premises MikroTik equipment has been updated.

Sources

Categories & features

  • Cybersecurity
  • Network Security
  • Vulnerability Management
  • Patch Management