CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root
MikroTik RouterOS before 7.24 contains an integer underflow (CWE-191) in its web management service, rated CVSS 9.8 by CISA. A single crafted HTTP request without credentials can achieve root code execution or a denial of service. Fixes are available in RouterOS 7.24.2 and 7.23.4.
- CVE-2026-84411: CVSS 9.8 integer underflow in RouterOS web service
- Flaw triggers before login check, reachable by anyone with network access
- Fixed in RouterOS 7.24.2 and 7.23.4, which also patch MikroTrick flaws
- ZoomEye found 2,861,901 instances matching the RouterOS fingerprint
Read next
Security