CISA flags critical pre-auth RCE bug in MikroTik RouterOS
CISA has issued an advisory for CVE-2026-84411, a critical integer underflow bug in MikroTik RouterOS's web-management HTTP handling that can be triggered before authentication. A single crafted request could let an unauthenticated attacker execute code as root or crash the device. Versions below 7.24 are affected, and the agency says the vendor advises upgrading to 7.23 or later, though it hasn't published its own advisory yet.