Skip to content

Security2 publishers2 min readPublished

CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.

The Watch · Security desk

Illustration accompanying CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

What happened

  • CISA released the advisory on September 29, 2026, after an anonymous researcher reported the flaw to the agency.
  • The same crafted request can instead be used to cause a denial of service, according to CISA.
  • CISA lists the communications and information technology sectors as affected, with RouterOS deployed worldwide.
  • MikroTik had not published its own security advisory for the flaw when BleepingComputer reported CISA's alert.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Operators on the 7.23 long-term branch must either move to stable 7.24.4 or stay put and rely on access controls until MikroTik or CISA settles which builds are fixed.
  • exposure Routers with web management answering from the internet or from untrusted internal segments can be attacked by anyone who can send them packets, with no credentials to steal first.
  • precedent Botnets already go after MikroTik flaws, so the gap before exploitation starts depends on how soon technical details for this one become public.

The preconditions are short. An attacker needs network access to the RouterOS web management service and one crafted request, with no account on the device [3]. The flaw sits ahead of the login check. "The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication," CISA wrote [2]. The weakness is filed as CWE-191, integer underflow or wraparound [4].

The version guidance does not agree with itself. CISA lists every RouterOS release below 7.24 as affected [5]. The same advisory says MikroTik recommends updating to 7.23 or later [6]. According to BleepingComputer, MikroTik's current long-term build is 7.23.7 and its current stable build is 7.24.4, both available since September 16 [7]. Read literally, 7.23.7 meets the vendor's floor and still falls inside CISA's affected range [1]. Of the two current builds, only 7.24.4 sits outside it [2]. Both had been out for 13 days when CISA published [3]. BleepingComputer asked MikroTik and CISA to clarify which versions are affected and had no answer at publication [8].

CISA's recommended practices are its standard control-system list: keep devices off the internet, put control networks behind firewalls isolated from business networks, and use updated VPNs for remote access [13]. For this bug the control that matters is narrower. The advisory's only stated precondition is network reach to the web management service [4]. Restricting which hosts can reach that service closes the path for every host outside the allowed set, whatever version the router runs [4].

Hackers and botnet malware often target MikroTik flaws, BleepingComputer reported [15]. Poland's CERT recently warned, according to BleepingComputer, that attackers chained CVE-2026-67276 and CVE-2026-86060 to take full control of RouterOS devices with SSH exposed to the internet [16]. That chain needed two flaws and an open SSH service [16]. CVE-2026-84411 needs one request to the web interface [1][3].

What to watch

  • MikroTik publishing its own advisory that names fixed builds, and in particular whether 7.23.7 carries the fix.
  • CISA revising the advisory's affected range to match the vendor's 7.23 floor, or MikroTik raising that floor to 7.24.
  • Technical details or a proof of concept from the anonymous reporter, or a first report of exploitation to CISA.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories