CVE-2026-84411: MikroTik RouterOS Integer Underflow

Published Oct 2, 2026
·
Updated

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

Affected Software

1 affected component
Mikrotik RouterOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MikroTik RouterOS to a version that resolves this vulnerability.

    Fixed in 7.24

Event History

Oct 2, 2026
CVE Published
via MITRE·10:09 PM
Data Sourced
via MITRE·10:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Apr 21, 58725
Event
via NVD·12:53 AM

Frequently Asked Questions

1

Who is exposed to exploitation?

Any affected MikroTik RouterOS device with its web management service reachable by a network attacker is exposed. Exploitation does not require authentication or user interaction.

2

What does an attacker need to do to exploit this issue?

An attacker needs network access to the RouterOS web management service and can trigger the flaw with a single crafted HTTP request body. The reported impact includes root-level arbitrary code execution or denial of service.

3

Is this limited to authenticated administrators or nondefault configurations?

No. The vulnerable HTTP request handling is reachable before authentication, so administrative credentials are not required. The available information does not state whether the web management service is enabled by default.

4

What can be done if updates cannot be applied immediately?

Restrict network access to the RouterOS web management service so untrusted network attackers cannot reach it. The provided information does not identify a configuration-level fix or other mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203