chiprook
← Security
SecurityOctober 3, 2026, 21:20

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root

MikroTik RouterOS before 7.24 contains an integer underflow (CWE-191) in its web management service, rated CVSS 9.8 by CISA. A single crafted HTTP request without credentials can achieve root code execution or a denial of service. Fixes are available in RouterOS 7.24.2 and 7.23.4.

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root
#MikroTik#RouterOS#CISA
Read next
Security

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

Security

CVE-2026-86060 in RouterOS: admin takeover without credentials

Security

CISA adds Microsoft SharePoint and MikroTik RouterOS flaws to KEV catalog

Security

MikroTik patches three RouterOS flaws, including SSH auth bypass