CISA has published advisory ICSA-26-272-06 for CVE-2026-84411, a critical (CVSS 9.8) integer underflow in the MikroTik RouterOS web management service. The bug is reachable before authentication, and CISA states that a single crafted HTTP request can lead to code execution as root or a denial of service. This is a separate flaw from the SSH-based MikroTrick chain disclosed in early September.

What happened

The weakness is classified as CWE-191 (integer underflow). It sits in the code that handles HTTP request bodies in RouterOS’s web management service, which backs WebFig and the REST interface. The vulnerable code runs before any login check, so an attacker needs no credentials, no session and no user interaction. Network reachability to the HTTP or HTTPS management port is enough.

An underflow in a length calculation at this layer typically produces an oversized copy or allocation. Depending on the build and memory layout, that gives either a crash (the device reboots, or the web service restarts) or controlled memory corruption. CISA describes the upper bound as root-level code execution.

Affected versions

  • RouterOS versions earlier than 7.24 are listed as affected.
  • MikroTik’s stable channel has since moved on (7.24.4 stable and 7.23.7 long-term were reported as available from September 16). Check the vendor changelog for the exact fixed build on your channel, because secondary sources disagree on the minimum safe version. Treat anything older than the current stable or long-term release as suspect.

Exploitation status

At time of writing there is no confirmed in-the-wild exploitation of CVE-2026-84411 and no public proof-of-concept that we could verify. Do not read that as low risk. MikroTik devices are a long-standing target for botnet operators and state-linked actors, and the recent MikroTrick exploitation showed attackers moving within days of disclosure. A single-request, pre-auth, root-level bug in a service that is frequently exposed to the internet is the kind of flaw that gets weaponized quickly once someone diffs the patch.

Context for exposure: Shadowserver counted roughly 122,500 RouterOS devices with SSH reachable from the internet in early September. Web management exposure is typically in the same order of magnitude, since many deployments leave WebFig enabled on the WAN interface by default-style configurations or forget it after initial setup.

Impact

  • Full compromise of the router with root privileges: traffic interception, DNS and routing manipulation, credential capture, tunnel pivoting into internal networks.
  • Persistent footholds on edge hardware, where EDR does not run and logging is usually thin.
  • Denial of service of branch and ISP-edge connectivity through repeated crashes.
  • Because RouterOS is common in ISP, WISP, branch-office and OT-adjacent networks, CISA published this under its ICS advisory series.

Mitigation

  1. Upgrade RouterOS to the current stable (7.24.x or later) or long-term (7.23.x latest) release. Reboot to apply, and verify with /system resource print.
  2. Remove web management from untrusted networks now. Disable the services you do not use: /ip service disable www,www-ssl. If you need them, bind them to a management VLAN or restrict with /ip service set www-ssl address=<mgmt-subnet> and an input-chain firewall rule that drops the rest.
  3. Audit for compromise on devices that were exposed. Review /user print, scheduler entries, scripts, /ip proxy, /ip socks, DNS static entries, and unexpected tunnels or NAT rules. Export the config and diff against a known-good copy.
  4. Watch for crashes. Unexplained reboots or web service restarts on exposed devices may indicate exploitation attempts; forward syslog off-box so evidence survives a reboot.
  5. Rotate credentials (local users, API, SNMP communities, VPN secrets) on any router that was internet-exposed and unpatched.
  6. Fleet owners should inventory RouterOS versions with the /system package print output or your NMS and prioritize internet-facing units first.

References