Critical flaw in MikroTik RouterOS enables remote code execution
US authorities have issued a warning about CVE-2026-84411, a serious vulnerability in MikroTik RouterOS that allows an unauthenticated attacker to run code with root privileges or disrupt service through a specially crafted web request. Versions below 7.24 are at risk. While exploitation has not been confirmed, router owners are urged to update their systems and follow network isolation practices to reduce exposure.
- CVE-2026-84411 affects RouterOS versions below 7.24
- Exploitable via the web management interface before authentication
- No current evidence of active attacks
- Users should update RouterOS and secure device access
Sources covering this
More in Cybersecurity
AI accelerates discovery of high-risk software vulnerabilities
Google’s Threat Intelligence Group reported that monthly vulnerability disclosures have doubled this year, increasing from 5,045 in…
OpenAI disrupts novel AI distillation attack it links to China
OpenAI announced it has stopped a coordinated attempt to extract and distill reasoning capabilities from its AI systems, attributing a…
Cisco SD-WAN Manager vulnerability actively exploited
Cisco has disclosed a critical security vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is being exploited by attackers.
Unpatched Zimbra flaw exploited to steal emails and credentials
A critical security vulnerability in Zimbra Collaboration Suite has been exploited by attackers to access emails and authentication data…