The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could allow hackers to run code from afar or stop the system from working.
Tracked as CVE-2026-84411, the security issue is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling. CISA says that single crafted request can produce code execution with root privileges or denial of service.
CISA says that MikroTik RouterOS versions under 7.24 have a problem. They also recommend that users update to version 7.23 or higher to reduce the risk. The newest stable version of MikroTik RouterOS is 7.24.4. The latest long-term version is 7.23.7. Both have been available since September 16.
CISA’s recommendations to MikroTik router owners include the following defensive actions:
Keep control systems inaccessible from the internet.
Place control networks and remote devices behind firewalls, isolated from business networks.
Use updated VPNs for remote access and secure all connected devices.
Although no active exploitation of CVE-2026-84411 has been publicly disclosed, hackers and botnet malware often target MikroTik flaws.
Cisco
Cisco put out security updates to fix a serious zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504). Attackers are using this flaw to gain admin access.
Formerly known as SD-WAN vManage, Catalyst SD-WAN Manager is network management software that lets admins monitor and manage up to 6,000 SD-WAN devices from a single dashboard.
“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,” the company warned on Wednesday. “Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.”
The CVE-2026-76504 flaw affects all setups, no matter how they are configured. It was found in how the system manages API sessions for authentication. This issue lets attackers who don’t have permission access the system from afar with admin rights.
“This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint,” Cisco added.
“An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system.”
| Cisco Catalyst SD-WAN Release | First Fixed Release |
|---|---|
| Earlier than 20.9 | Migrate to a fixed release. |
| 20.9 | 20.9.10.1 |
| 20.12 | 20.12.8.2 |
| 20.15 | 20.15.6.1 |
| 20.18 | 20.18.4.1 |
| 26.1 | 26.1.2.1 |
| 26.2 | 26.2.1 |
InfoSecBulletin Cybersecurity for mankind
