CISA AdvisoriesSecurity updates
MikroTik RouterOS
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.
The following versions of MikroTik RouterOS are affected:
RouterOS <7.24 (CVE-2026-84411)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
MikroTik
MikroTik RouterOS
Integer Underflow (Wrap or Wraparound)
Background
Critical Infrastructure Sectors: Communications, Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Latvia
Vulnerabilities
Expand All +
CVE-2026-84411
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
View CVE Details
Affected Products
MikroTik RouterOS
Vendor:
MikroTik
Product Version:
MikroTik RouterOS: <7.24
Product Status:
known_affected
Remediations
Vendor fix
MikroTik recommends users update RouterOS to version 7.23 or later. The upgrade can be downloaded from the MikroTik website.
https://mikrotik.com/download
Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound)
Metrics
CVSS Version
Base Score
Base Severity
Vector String
3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
4.0
9.3
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Acknowledgments
An anonymous researcher reported thi