Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution

Critical MikroTik RouterOS Integer Underflow Vulnerability (TL-2026-2805), also tracked as ICSA-26-272-06, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-30. It has no confirmed attribution, affects MikroTik RouterOS, references 1 CVE (CVE-2026-84411), maps to 7 MITRE ATT&CK techniques (T1040, T1059, T1133), and is covered by 9 detection rules and 6 indicators of compromise.

Key facts for TL-2026-2805

Threat ID
TL-2026-2805
Also known as
ICSA-26-272-06
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
communications, information-technology
Target regions
Global
Detection rules
9
Indicators of compromise
6

CVE-2026-84411 is an integer underflow (CWE-191) in the MikroTik RouterOS web management service, affecting versions earlier than 7.24 and rated CVSS 9.8 Critical. A single crafted unauthenticated request can yield root code execution or denial of service. CISA (ICSA-26-272-06) reported no public exploitation at disclosure.

How Critical MikroTik RouterOS Integer Underflow Vulnerability works

CVE-2026-84411 is an integer underflow (wraparound, CWE-191) in the HTTP request body handling of the MikroTik RouterOS web management service. CISA advisory ICSA-26-272-06, released 2026-09-29 and covered by GBHackers on 2026-09-30, states the flaw is reachable before authentication over the network, so an unauthenticated remote attacker can send a single crafted request to execute arbitrary code as root or crash the service (denial of service). The CVSS v3.1 base score is 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and the CVSS v4.0 score is 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). The vulnerability was reported to CISA by an anonymous researcher.

Impact per the sources: full device compromise, network pivoting, traffic interception, or persistent access on the router. Because RouterOS devices sit at the network edge and often expose management services to the internet, a compromised router gives an attacker a position to observe or redirect traffic for downstream networks. Affected sectors named by CISA are Communications and Information Technology.

Exploitation status: CISA stated it had received no reports of public exploitation specifically targeting CVE-2026-84411 at publication, no public PoC, threat actor, malware family, or network IOC is documented in the available sources. GBHackers notes that internet-facing network appliances are routinely scanned after vulnerability disclosures, so opportunistic scanning of exposed RouterOS web services should be expected.

Version caveat (unresolved in sources): the affected range is stated as RouterOS earlier than 7.24, but the CISA advisory remediation text says to update to RouterOS 7.23 or later, while the GBHackers article says 7.24 or later. At the time of research the MikroTik changelog page listed 7.23.7 (2026-09-16) as the newest release and no 7.24 entry or CVE-2026-84411 changelog line was visible, and NVD returned no record for the CVE yet. Defenders should confirm the fixed build against the MikroTik download/changelog pages and default to the latest available release.

Defensive priorities: identify all RouterOS devices, remove or restrict internet exposure of the web management service (HTTP/HTTPS), upgrade to the fixed release, review router logs for anomalous or malformed requests to the web service and unexpected configuration or account changes, preserve logs, and report suspicious activity to CISA.

MITRE ATT&CK techniques used in TL-2026-2805

Credential Access

T1040 Network Sniffing; T1557 Adversary-in-the-Middle

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1499.004 Application or System Exploitation

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Critical MikroTik RouterOS Integer Underflow Vulnerability

  • MikroTik — RouterOS
    Vulnerable versions: earlier than 7.24
    Fixed in: 7.24 or later (CISA advisory remediation text cites 7.23 or later; confirm at mikrotik.com/download)

Remediation for Critical MikroTik RouterOS Integer Underflow Vulnerability

Patches

  • Upgrade to the fixed RouterOS release (advisory text cites 7.23 or later; affected range is earlier than 7.24 - confirm the fixed build at https://mikrotik.com/download)

Immediate actions

  • Inventory all MikroTik RouterOS devices and identify those running versions earlier than 7.24
  • Prioritize internet-exposed management services and remote administration interfaces
  • Restrict the RouterOS web management service (HTTP/HTTPS) to trusted management networks or disable it
  • Preserve router logs of suspicious activity and report findings to CISA

Workarounds

  • Disable the web management service (www / www-ssl) if not required
  • Apply firewall input-chain rules limiting management access to specific source addresses

Longer-term hardening

  • Keep RouterOS on a current release channel and monitor MikroTik changelogs for security fixes
  • Never expose router management planes directly to the internet; use VPN or a management VLAN
  • Forward router logs to a SIEM and alert on web service crashes/reboots and config changes

CVEs associated with Critical MikroTik RouterOS Integer Underflow Vulnerability

CVE-2026-84411

Weaknesses (CWE) in Critical MikroTik RouterOS Integer Underflow Vulnerability

CWE-191

Timeline of Critical MikroTik RouterOS Integer Underflow Vulnerability

  • CISA published ICSA-26-209-05 for a separate MikroTik RouterOS API flaw (no login lockout), context for recent RouterOS scrutiny
  • CISA published ICSA-26-211-01 for CVE-2026-14227 (RouterOS API insufficient session expiration exposing WireGuard private key), a separate flaw
  • MikroTik released RouterOS 7.23.6 per the vendor changelog page
  • MikroTik released RouterOS 7.23.7, the newest release listed on the changelog page at research time
  • CISA stated it had received no reports of public exploitation targeting CVE-2026-84411
  • CISA released advisory ICSA-26-272-06 disclosing CVE-2026-84411, an unauthenticated integer underflow in the RouterOS web management service reported by an anonymous researcher
  • GBHackers published coverage warning that internet-facing RouterOS devices are at risk of remote code execution; NVD had no record for the CVE yet

Sources cited for Critical MikroTik RouterOS Integer Underflow Vulnerability

More in vulnerability

Detection coverage for TL-2026-2805

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2805 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats