MikroTik RouterOS CVE-2026-84411 (CISA ICSA-26-272-06, 29 Sep): pre-auth web-mgmt integer underflow → root RCE/DoS (CVSS 9.8)
CISA ICS advisory ICSA-26-272-06 (29 September 2026) assigns CVE-2026-84411 (CVSS 3.1 9.8 / CVSS 4.0 9.3 Critical) to MikroTik RouterOS web management: an integer underflow (CWE-191) in HTTP request body handling reachable before authentication lets an unauthenticated network attacker achieve arbitrary code execution as root or denial of service with a single crafted request. Affected: RouterOS <7.24. CISA remediation text: MikroTik recommends update to RouterOS 7.24 or later (download mikrotik.com/download). CISA: no known public exploitation specifically targeting this CVE at publication. Distinct from desk mikrotik-routeros-20260905 (CERT.PL MikroTrick SSH chain CVE-2026-67279/86060 and related Sep disclosures). Until patched: keep web management off the internet; firewall-isolate management planes; prefer VPN for remote admin. Primary: CISA ICSA-26-272-06; wire: BleepingComputer 30 Sep (RSS/homepage 403 from desk egress — opened via search/WebFetch).
- Product
- MikroTik RouterOS (web management service)
- Versions
- Affected: RouterOS <7.24 (per CISA). Patch-to per CISA: RouterOS 7.24 or later. Note: BC reported conflicting “7.23 or later” vendor wording — desk follows CISA primary (7.24+).
- CVSS
- (CVSS 3.1) / 9.3 (CVSS 4.0)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H; CVSS:4.0/AT:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- Upgrade RouterOS to 7.24 or later (CISA); remove internet exposure of Winbox/WebFig/WWW until patched.
Primary: CISA — ICSA-26-272-06 MikroTik RouterOS (CVE-2026-84411, 29 Sep 2026) · Vendor: MikroTik — RouterOS downloads · CVE: CVE-2026-84411, CVE-2026-67279 · BleepingComputer — CISA warns MikroTik pre-auth RCE (30 Sep 2026)
