CISA issued advisory ICSA-26-272-06 for CVE-2026-84411, a critical CVSS 9.8 integer-underflow flaw in MikroTik RouterOS web-management HTTP request handling. A remote, unauthenticated attacker can reportedly send a crafted request to execute arbitrary code with root privileges or trigger denial of service on affected RouterOS releases before version 7.24. CISA reported no evidence of active exploitation at publication, while noting ambiguity in referenced remediation guidance that cited version 7.23 or later despite identifying versions below 7.24 as affected.
An internet-exposed compromised router could permit traffic interception or redirection, DNS and firewall manipulation, persistence, internal reconnaissance, and lateral movement into enterprise or operational-technology networks. Organizations should upgrade to RouterOS 7.24 or later, remove management interfaces from public exposure, segment router management networks, and require secured VPN access for remote administration. Defenders should investigate unexpected configuration or script changes, DNS modifications, anomalous outbound traffic, and unknown accounts.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CISA published advisory ICSA-26-272-06 for CVE-2026-84411, a CVSS 9.8 pre-authentication integer-underflow vulnerability affecting MikroTik RouterOS versions earlier than 7.24. The flaw may allow an unauthenticated remote attacker to execute code with root privileges or cause denial of service; CISA reported no known public exploitation targeting the CVE.
MikroTik made RouterOS 7.24.4, the latest stable release, and RouterOS 7.23.7, the latest long-term release, available. CISA's reporting contained conflicting version guidance for CVE-2026-84411, while other reporting identified 7.24 or later as the mitigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.