A new MikroTik RouterOS flaw is not the exploited one, and CISA changed its fix version from 7.23 to 7.24
CISA's 29 September advisory covers CVE-2026-84411, a new pre-authentication flaw in the RouterOS web service, not the SSH flaw already in the exploited catalogue. Its fix version changed from 7.23 to 7.24 within 24 hours, and MikroTik has published nothing.
By Parminder Kumar Sharma · · 11 min read

A new flaw, and a fix version that changed in a day
CISA's machine-readable copy of its MikroTik RouterOS advisory said on 29 September that the fix was version 7.23 or later. Twenty three hours and 43 minutes later, in a second commit to the same file with the revision note "Fixing upgrade version typo", it said 7.24 or later. The two numbers sit on different release lines. 7.23 is MikroTik's long-term line, whose newest build is 7.23.7. 7.24 is the stable line. On CISA's own affected range, RouterOS below 7.24, the newest long-term build is still inside it.
This is a new flaw, not the one already in the exploited catalogue. The catalogue entry of 25 September is CVE-2026-67279, a fault in the SSH server, covered in MikroTik withheld the details for a day and in a three day deadline for flaws public for weeks. The flaw in today's coverage is CVE-2026-84411, an integer underflow in the web management service's handling of HTTP request bodies, reachable before login. CISA says one crafted request can give code execution as root or a denial of service. BleepingComputer's report, which I read at about 20:00 BST, is about this flaw and still carries the superseded 7.23 wording.
What that does not establish. It does not establish that anyone is exploiting CVE-2026-84411. CISA says no known public exploitation specifically targeting it has been reported, and the flaw is not in the exploited catalogue, version 2026.09.30, released at 16:59 UTC. It does not establish that the long-term line is unfixed, only that no source says it is fixed. It does not establish how many devices are exposed, because no source counts devices running this service. And it does not establish that any workaround closes the flaw, because MikroTik has published no advisory or workaround for this CVE. All of this is as of 20:15 BST on 30 September, and could change within the hour.
New, and not the flaw in the exploited catalogue
CVE-2026-84411 beside CVE-2026-67279, from CISA advisory ICSA-26-272-06, NVD, the exploited catalogue and MikroTik, read at 20:15 BST on 30 September 2026
| Field | CVE-2026-84411 (new) | CVE-2026-67279 (in the catalogue) |
|---|---|---|
| Component | Web management service, HTTP request body handling | SSH server, after a client-requested rekey |
| Weakness | CWE-191, integer underflow | CWE-841, improper enforcement of behavioural workflow |
| Source | CISA ICS advisory, 29 Sep. An anonymous researcher reported it to CISA | CERT Polska, per the NVD record |
| Scores | CVSS 3.1 of 9.8 and 4.0 of 9.3, both listed in CISA's advisory | CVSS 3.1 of 6.5 from NVD and 4.0 of 6.9 from CERT Polska |
| Exploitation | No known public exploitation reported to CISA. Not in the catalogue | In the catalogue since 25 Sep, due 28 Sep. Chained with CVE-2026-86060 in attacks CERT Polska dates from 2 Sep |
| NVD record | None returned at 20:15 BST | Analysed, last modified 26 Sep |
| MikroTik advisory | None on its security page | 3 Sep page, which does not name this CVE |
| Fixed in | 7.24 or later per CISA, first published as 7.23 or later | 6.49.21, 7.23.4 and 7.24.2 per NVD |
The flaw in the catalogue scores lower than the new one. On its own CVE-2026-67279 is 6.5 at NVD, though its chain partner CVE-2026-86060 is 9.8. The new flaw is 9.8 in CISA's advisory, which does not say who assigned the score; NVD and MikroTik have published none. Scores describe what a flaw could do, and the catalogue records what someone has been seen doing, so keep "critical" and "exploited" as different words.
CISA's machine-readable file carries one more signal, an SSVC note reading E:N and A:Y, stamped 24 September: exploitation none, automatable yes. SSVC defines automatable as attackers being able to reliably automate the first four kill chain steps, and its own guidance says yes is the safer answer when nothing is known. My reading, which is inference, is that the flag is caution, not a finding that anyone has automated this. The file was generated on 24 September, five days before publication. No source says when the researcher reported to CISA or when MikroTik was told.
The fixed range covers one release line, and the vendor is silent on the other
MikroTik ships several lines at once. The newest builds at 20:15 BST are 7.24.4 on the stable line and 7.23.7 and 6.49.22 on the long-term lines, all dated 16 September in MikroTik's changelogs. On the record I read, from 14 August it has shipped five stable builds numbered 7.24 or above, two 7.25 beta builds, and six long-term builds: 7.23.4 to 7.23.7, 6.49.21 and 6.49.22. None of the six is at or above 7.24, so none is named as fixed. Those counts are derived from MikroTik's changelog and forum announcements; nobody states them. Whether version 6 holds the flawed code at all is not stated.
MikroTik's changelogs do not settle it. The web service lines from 7.24 onward, and in the long-term builds since 3 September, are below. None names CVE-2026-84411.
Every www line, and the webfig stability lines, in MikroTik's changelogs for 7.24 to 7.24.4 and 7.23.4 to 7.23.7, shown as component: text. 7.24 also has webfig lines on keep-alive traffic and graphs. 7.23.5, 7.23.7, 7.24.4 and both 6.49 builds carry none
| Build, line and date | Web service lines in the changelog | Names a CVE? |
|---|---|---|
| 7.24, stable, 14 Aug | webfig: improved underlying encryption and stability processing | No |
| 7.24.1, stable, 21 Aug | www: improve service responsiveness when receiving malformed packets | No |
| 7.24.2, stable, 3 Sep | webfig: improve stability. www: improve stability | No |
| 7.23.4, long-term, 3 Sep | webfig: improve stability. www: improve stability | No |
| 7.23.6, long-term, 14 Sep | www: improve stability | No |
| 7.24.3, stable, 14 Sep | webfig: improve stability. www: improve stability | No |
I cannot tell from these lines which build first fixed CVE-2026-84411, or whether any of them did. MikroTik uses the same phrase for security and non-security changes. The 7.23.6 line for crypto reads "improve stability" with CVE-2026-67278 in brackets, and the 6.49.22 line for system reads the same with CVE-2026-67281. CERT Polska warned on 5 September that it could not rule out flaws the vendor had not described in its changelog. The SANS Internet Storm Center's 30 September Stormcast voiced the same worry: no advisory on MikroTik's site, CISA treating 7.24 as patched, and a long-term build not yet on 7.24 that may be vulnerable. That is commentary, not a finding.
MikroTik can name a fix for each line when it chooses. Its 16 September advisory for CVE-2026-52346 lists 7.22.2 for stable and 7.21.4 for long-term, and the NVD record for CVE-2026-67279 lists fixed builds on three lines. For CVE-2026-84411 nobody has done that for the long-term line.
Three labels that are not controls
Long-term names a support policy, not a patch level. Anyone who read 7.23 or later in CISA's first version and saw 7.23.7 on the long-term channel would have concluded they were covered. The corrected text says otherwise, and the vendor has not said which is right.
Improve stability covers trivial and security changes alike, as the two bracketed CVEs above show. A missing CVE tag is not evidence of no fix, and a stability line is not evidence of a minor one.
Critical is a score, and the flaw in the exploited catalogue scores lower. Nor is the industrial control system label a control. The advisory's recommended practices are generic: keep control systems off the internet, put them behind firewalls, use updated VPNs. They are sensible, but they mention no service, port or setting, so they are not a mitigation for this flaw.
Stated, and not stated
What the record says and does not say about CVE-2026-84411 at 20:15 BST on 30 September 2026, from CISA, NVD, CVE Services and MikroTik
| Question | Stated | Not stated |
|---|---|---|
| Is it exploited? | CISA: no known public exploitation reported to it. Not in the catalogue | Private exploitation, vendor telemetry, anyone else's sensors |
| Which versions? | RouterOS below 7.24, web management service, per CISA | Whether version 6 holds the code. Which configurations are reachable |
| Is there a fix? | CISA: 7.24 or later, corrected on 30 Sep from 7.23 or later | MikroTik's own statement. The first fixed build. Any long-term fix |
| How severe? | CVSS 3.1 of 9.8 and 4.0 of 9.3 in CISA's advisory. SSVC: exploitation none, automatable yes | Any NVD or vendor score. Who assigned CISA's scores. How reliable exploitation is |
| Is there a workaround? | Generic control system practices from CISA | A vendor workaround. Whether disabling the web service closes it |
| How many devices? | Nothing for this service | Any exposure count. BleepingComputer's 122,500 devices with an exposed SSH interface on 5 Sep, from Shadowserver, concerns a different service |
| What about the UK? | CISA lists deployment as worldwide and the vendor's headquarters as Latvia | Any UK figure or statement. I found no NCSC item, but its search page did not load without scripts, so that is not evidence of absence |
One row needs care. On 4 September the account that posted MikroTik's advisory on its forum said, about the September flaws, that Winbox, Webfig and SSH should not be exposed to the internet. CERT Polska's interim advice for its six flaws was to disable or block the SSH, WWW, WWW-SSL and bandwidth-test services. Neither statement is about CVE-2026-84411. Inference: CISA says a network attacker reaches the flaw through the web management service, so a device whose web service cannot be reached from untrusted networks cannot be reached that way. That is reasoning, not a vendor finding, and it does not help where the service must stay open.
What to do, in the order worth doing
Take this with you
Defender checklist for CVE-2026-84411
- Record the build and the release line, stable, long-term 7.x or 6.x, of every RouterOS device you run. You cannot answer the channel question from memory.
- Find which of them answer on the web management service from outside, including through port forwards, permissive firewall rules and management networks reachable from guest or tenant networks. Test from outside, not from the configuration alone.
- Close that reach first. Limit the web service to a named management network or a VPN, or turn it off where it is not used. This does not wait on MikroTik.
- Move stable-line devices to 7.24.4, the newest stable build at 20:15 BST on 30 September. Do not stop at 7.24.2 or 7.23.4, which NVD says carry an incomplete fix for CVE-2026-67278, and avoid 7.24.3 and 7.23.6, which MikroTik says can delete modem firmware on some LTE models. 7.24.4 and 7.23.7 correct that.
- For long-term devices, ask MikroTik in writing whether any 7.23.x or 6.49.x build contains the fix for CVE-2026-84411. Its security page gives security@mikrotik.com. Until it answers, treat long-term builds as inside CISA's range and keep their web service closed.
- On anything that was reachable, review the log for unexplained reboots or service restarts, and the configuration for unknown users, scripts, scheduler entries, proxy and tunnel settings. The Flagged check shipped with the September SSH fixes, so a clean result says nothing about this flaw.
- If you find signs of compromise, isolate the device, keep its logs and configuration, then reset it, rebuild from a trusted configuration and rotate credentials, as CERT Polska set out for the September attacks. Do not wait for the exploited catalogue, which lags the flaw.
- Read CISA's advisory and MikroTik's security page again tomorrow and at the end of the week. The fix version has already changed once, and MikroTik had said nothing at 20:15 BST.
The question this leaves
Fairness first. A typo corrected within a day is a process working, and a vendor that is silent for a day or so may simply be behind: BleepingComputer emailed both MikroTik and CISA and had no reply when it published. Nothing here accuses either of hiding anything. It says the record a defender needs does not yet exist.
The tidy reading is a critical flaw, no reported exploitation, a fix in 7.24, so update and move on. Each part is what the sources say. None of it is enough for a long-term user. CISA's own advisory had to be corrected once in 24 hours, the vendor has published nothing, and the changelog that would settle it says improve stability.
So the question is not whether you can reach 7.24. It is this: for the routers you run on the long-term line, who told you they are fixed, and what did they read?
Key facts
Sources
- PrimaryICS advisory ICSA-26-272-06, MikroTik RouterOS, released 29 September 2026; read in full for CVE-2026-84411, the affected range, the fix wording, the scores and the exploitation statementCISAaccessed 2026-09-30
- PrimaryThe advisory's CSAF file, current version: revision 2 'Fixing upgrade version typo', the SSVC stamp and the generator dateCISAaccessed 2026-09-30
- PrimaryCommit history of the CSAF file: the first commit of 29 September, 16:02 UTC, says 7.23 or later; the second, 30 September, 15:45 UTC, says 7.24 or laterCISA, on GitHubaccessed 2026-09-30
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.09.30, 1,730 entries, released 16:59 UTC: CVE-2026-84411 absent; entries for CVE-2026-67279, CVE-2026-86060 and CVE-2026-67277CISAaccessed 2026-09-30
- PrimaryNVD API query for CVE-2026-84411: zero results at 19:03 UTC and again at 19:15 UTC on 30 SeptemberNIST NVDaccessed 2026-09-30
- PrimaryCVE Services API query for CVE-2026-84411: returned CVE_RECORD_DNE at 19:03 UTC and again at 19:15 UTC on 30 SeptemberCVE Programaccessed 2026-09-30
- PrimaryNVD record for CVE-2026-67279, the SSH flaw: description, NVD 6.5 and CERT Polska 6.9 scores, fixed builds, referencesNIST NVDaccessed 2026-09-30
- PrimaryMikroTik security announcements page: newest entries are 16 September (CVE-2026-52346) and 3 September; nothing for CVE-2026-84411; security contactMikroTikaccessed 2026-09-30
- PrimaryMikroTik's 3 September 2026 advisory: fixed builds, the three CVEs it names, and its steps for administratorsMikroTikaccessed 2026-09-30
- PrimaryMikroTik changelog index, used for the release line and date of every build from 7.23.4 to 7.23.7 and 6.49.22MikroTikaccessed 2026-09-30
- PrimaryPlain text changelog files, one per build (7.24 to 7.24.4, 7.23.4 to 7.23.7, 6.49.21, 6.49.22, 7.25beta3, 7.25beta4), read for every www and webfig line and every bracketed CVEMikroTikaccessed 2026-09-30
- PrimaryRelease announcement thread for 7.24.4 (stable), 16 September, used for channel labels and announcement datesMikroTik forumaccessed 2026-09-30
- Primary'Important security update' thread, 4 September: the advisory text and the later advice not to expose Winbox, Webfig or SSH to the internetMikroTik forumaccessed 2026-09-30
- PrimaryCERT Polska warning of 5 September on the six September flaws: interim advice, the Flagged mechanism, and its caution about flaws not described in the changelogCERT Polskaaccessed 2026-09-30
- PrimarySSVC definition of the Automatable decision point, used to read the E:N/A:Y stamp in CISA's fileCERT/CCaccessed 2026-09-30
- Reported byThe news report this briefing starts from, published 30 September; it still carries CISA's superseded 7.23 wordingBleepingComputeraccessed 2026-09-30
- Reported byStormcast of 30 September 2026 and its transcript: commentary that the flaw is distinct from MikroTrick and may be silently patchedSANS Internet Storm Centeraccessed 2026-09-30
- Reported byReport of 26 September on the 25 September catalogue additions; covers CVE-2026-67279, not CVE-2026-84411; used only to separate the two storiesThe Hacker Newsaccessed 2026-09-30


