Vulnerability
Published 2026-09-29
Verified 2026-10-01

MikroTik RouterOS CVE-2026-84411 (CISA ICSA-26-272-06, 29 Sep): pre-auth web-mgmt integer underflow → root RCE/DoS (CVSS 9.8)

CISA ICS advisory ICSA-26-272-06 (29 September 2026) assigns CVE-2026-84411 (CVSS 3.1 9.8 / CVSS 4.0 9.3 Critical) to MikroTik RouterOS web management: an integer underflow (CWE-191) in HTTP request body handling reachable before authentication lets an unauthenticated network attacker achieve arbitrary code execution as root or denial of service with a single crafted request. Affected: RouterOS <7.24. CISA remediation text: MikroTik recommends update to RouterOS 7.24 or later (download mikrotik.com/download). CISA: no known public exploitation specifically targeting this CVE at publication. Distinct from desk mikrotik-routeros-20260905 (CERT.PL MikroTrick SSH chain CVE-2026-67279/86060 and related Sep disclosures). Until patched: keep web management off the internet; firewall-isolate management planes; prefer VPN for remote admin. Primary: CISA ICSA-26-272-06; wire: BleepingComputer 30 Sep (RSS/homepage 403 from desk egress — opened via search/WebFetch).

Product
MikroTik RouterOS (web management service)
Versions
Affected: RouterOS <7.24 (per CISA). Patch-to per CISA: RouterOS 7.24 or later. Note: BC reported conflicting “7.23 or later” vendor wording — desk follows CISA primary (7.24+).
CVSS
(CVSS 3.1) / 9.3 (CVSS 4.0)
Exploited in Australia?
unknown
Patch to
Upgrade RouterOS to 7.24 or later (CISA); remove internet exposure of Winbox/WebFig/WWW until patched.

Primary: CISA — ICSA-26-272-06 MikroTik RouterOS (CVE-2026-84411, 29 Sep 2026) · Vendor: MikroTik — RouterOS downloads · CVE: CVE-2026-84411, CVE-2026-67279 · BleepingComputer — CISA warns MikroTik pre-auth RCE (30 Sep 2026)

vulnerabilities network