Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
Critical MikroTik RouterOS Integer Underflow Vulnerability (TL-2026-2805), also tracked as ICSA-26-272-06, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-30. It has no confirmed attribution, affects MikroTik RouterOS, references 1 CVE (CVE-2026-84411), maps to 7 MITRE ATT&CK techniques (T1040, T1059, T1133), and is covered by 9 detection rules and 6 indicators of compromise.
Key facts for TL-2026-2805
- Threat ID
- TL-2026-2805
- Also known as
- ICSA-26-272-06
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- communications, information-technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
CVE-2026-84411 is an integer underflow (CWE-191) in the MikroTik RouterOS web management service, affecting versions earlier than 7.24 and rated CVSS 9.8 Critical. A single crafted unauthenticated request can yield root code execution or denial of service. CISA (ICSA-26-272-06) reported no public exploitation at disclosure.
How Critical MikroTik RouterOS Integer Underflow Vulnerability works
CVE-2026-84411 is an integer underflow (wraparound, CWE-191) in the HTTP request body handling of the MikroTik RouterOS web management service. CISA advisory ICSA-26-272-06, released 2026-09-29 and covered by GBHackers on 2026-09-30, states the flaw is reachable before authentication over the network, so an unauthenticated remote attacker can send a single crafted request to execute arbitrary code as root or crash the service (denial of service). The CVSS v3.1 base score is 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and the CVSS v4.0 score is 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). The vulnerability was reported to CISA by an anonymous researcher.
Impact per the sources: full device compromise, network pivoting, traffic interception, or persistent access on the router. Because RouterOS devices sit at the network edge and often expose management services to the internet, a compromised router gives an attacker a position to observe or redirect traffic for downstream networks. Affected sectors named by CISA are Communications and Information Technology.
Exploitation status: CISA stated it had received no reports of public exploitation specifically targeting CVE-2026-84411 at publication, no public PoC, threat actor, malware family, or network IOC is documented in the available sources. GBHackers notes that internet-facing network appliances are routinely scanned after vulnerability disclosures, so opportunistic scanning of exposed RouterOS web services should be expected.
Version caveat (unresolved in sources): the affected range is stated as RouterOS earlier than 7.24, but the CISA advisory remediation text says to update to RouterOS 7.23 or later, while the GBHackers article says 7.24 or later. At the time of research the MikroTik changelog page listed 7.23.7 (2026-09-16) as the newest release and no 7.24 entry or CVE-2026-84411 changelog line was visible, and NVD returned no record for the CVE yet. Defenders should confirm the fixed build against the MikroTik download/changelog pages and default to the latest available release.
Defensive priorities: identify all RouterOS devices, remove or restrict internet exposure of the web management service (HTTP/HTTPS), upgrade to the fixed release, review router logs for anomalous or malformed requests to the web service and unexpected configuration or account changes, preserve logs, and report suspicious activity to CISA.
MITRE ATT&CK techniques used in TL-2026-2805
Credential Access
T1040 Network Sniffing; T1557 Adversary-in-the-Middle
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Reconnaissance
Affected products and versions in Critical MikroTik RouterOS Integer Underflow Vulnerability
- MikroTik — RouterOS
Vulnerable versions: earlier than 7.24
Fixed in: 7.24 or later (CISA advisory remediation text cites 7.23 or later; confirm at mikrotik.com/download)
Remediation for Critical MikroTik RouterOS Integer Underflow Vulnerability
Patches
- Upgrade to the fixed RouterOS release (advisory text cites 7.23 or later; affected range is earlier than 7.24 - confirm the fixed build at https://mikrotik.com/download)
Immediate actions
- Inventory all MikroTik RouterOS devices and identify those running versions earlier than 7.24
- Prioritize internet-exposed management services and remote administration interfaces
- Restrict the RouterOS web management service (HTTP/HTTPS) to trusted management networks or disable it
- Preserve router logs of suspicious activity and report findings to CISA
Workarounds
- Disable the web management service (www / www-ssl) if not required
- Apply firewall input-chain rules limiting management access to specific source addresses
Longer-term hardening
- Keep RouterOS on a current release channel and monitor MikroTik changelogs for security fixes
- Never expose router management planes directly to the internet; use VPN or a management VLAN
- Forward router logs to a SIEM and alert on web service crashes/reboots and config changes
CVEs associated with Critical MikroTik RouterOS Integer Underflow Vulnerability
CVE-2026-84411
Weaknesses (CWE) in Critical MikroTik RouterOS Integer Underflow Vulnerability
CWE-191
Timeline of Critical MikroTik RouterOS Integer Underflow Vulnerability
- CISA published ICSA-26-209-05 for a separate MikroTik RouterOS API flaw (no login lockout), context for recent RouterOS scrutiny
- CISA published ICSA-26-211-01 for CVE-2026-14227 (RouterOS API insufficient session expiration exposing WireGuard private key), a separate flaw
- MikroTik released RouterOS 7.23.6 per the vendor changelog page
- MikroTik released RouterOS 7.23.7, the newest release listed on the changelog page at research time
- CISA stated it had received no reports of public exploitation targeting CVE-2026-84411
- CISA released advisory ICSA-26-272-06 disclosing CVE-2026-84411, an unauthenticated integer underflow in the RouterOS web management service reported by an anonymous researcher
- GBHackers published coverage warning that internet-facing RouterOS devices are at risk of remote code execution; NVD had no record for the CVE yet
Sources cited for Critical MikroTik RouterOS Integer Underflow Vulnerability
- Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution
- CISA ICS Advisory ICSA-26-272-06 - MikroTik RouterOS
- MikroTik RouterOS changelogs
- MikroTik RouterOS downloads
- CVE Record CVE-2026-84411
- NVD API - CVE-2026-84411 (no record at time of research)
- MikroTik RouterOS CRA Class I after CISA July 2026 WireGuard advisory (related prior MikroTik advisories)
More in vulnerability
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
Detection coverage for TL-2026-2805
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2805 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.