MikroTik RouterOS pre-auth RCE is a 9.8
Integer underflow in the HTTP handler is reachable without authentication and needs only a single crafted request, a rare attack surface for router firmware that puts this in the top remediation tier.
TL;DR
CISA issued ICSA-26-272-06 for CVE-2026-84411, a CVSS 9.8 unauthenticated remote code execution flaw in the web management service of MikroTik RouterOS versions below 7.24. An attacker can achieve root-level code execution or denial of service with one crafted HTTP request, no authentication, no user interaction. MikroTik directs users to upgrade to version 7.23 or later. CISA states no known public exploitation has been reported to it at this time.
CVE-2026-84411 is an integer underflow (CWE-191) in the HTTP request body handling of the web management service. The vulnerability is reachable before authentication, which means any network-connected attacker can trigger it. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects the worst-case combination: network-reachable, low complexity, no privileges, no user interaction, and a complete confidentiality/integrity/availability impact.
That's a short list of router firmware bugs. Most high-severity RouterOS flaws CISA has flagged this year cluster in the API, BGP, or VPN services, session management weaknesses, rate-limiting gaps, BGP message parsing. A pre-auth integer underflow in the web stack is a different category of problem. It doesn't require the attacker to be on-path, authenticated, or patient.
MikroTik says upgrade to 7.23 or later. The advisory lists affected versions as "<7.24," and the remediation text points to 7.23+. CISA's language, "MikroTik recommends users update RouterOS to version 7.23 or later", leaves a gap between what's patched and what's explicitly called fixed. The advisory doesn't state whether 7.23 fully resolves the underflow or if 7.24 is the complete remediation. Operators running 7.23 should verify with MikroTik directly.
CISA says no known public exploitation has been reported to it. The advisory was published September 29, 2026. The researcher is listed as anonymous. That combination (anonymous report, public advisory, no confirmed exploitation) is a window. How long it stays open depends on how fast operators move.
For anyone running RouterOS below 7.24 with the web management interface reachable, the remediation path is straightforward: upgrade and restrict management access. CISA's standard ICS guidance applies, minimize network exposure, isolate management interfaces behind firewalls, use VPNs for remote access. But on this one, the upgrade is the only real mitigation. An integer underflow in the pre-auth path can't be firewalled around.
Published ·Deep Fathom