A second critical hole in MikroTik routers, and this one is in the login page
Three weeks ago the problem with MikroTik routers was SSH. Attackers were taking over boxes that had SSH facing the internet, without a password, and CERT Polska had evidence going back to 2 September. Now there is a second one, in the other door.
CVE-2026-84411 lives in RouterOS's web management service, the page you open in a browser to configure the thing. It is an integer underflow in how HTTP request bodies are handled, and the handling happens before any login check. One crafted request is enough to run code as root or knock the router offline. The score is 9.8 out of 10. CISA published an advisory on 29 September, ICSA-26-272-06, and BleepingComputer picked it up the next day. Nobody has reported it being used in attacks yet, and MikroTik has not published an advisory of its own.
Everything below RouterOS 7.24 is affected. The fixed builds, 7.24.2 and 7.23.4, have been out since mid-September, which means many people already patched this without knowing what they were patching. Updating is System, then Packages, then Check For Updates, then a reboot.
The part worth doing while you are in there is the same as last time: look at whether the web interface and SSH can be reached from the internet at all, and switch them off if they can. A home router with default rules usually blocks both, but defaults get changed by whoever set the thing up. If you are not sure what hardware you actually have, Tendvane's network scan lists every device on your home network, router included, which is the quickest way to find out whether any of this applies to you.