CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

MikroTik RouterOS, pre-authentication integer underflow in the web management service (WebFig, www/www-ssl): one crafted request can crash the service or run code as root (CVSS 3.1 9.8); fixed in 7.24 on v7 stable, long-term releases pending

cve · CVE-2026-84411

Coverage
1
first 2026-10-10 → last 2026-10-10
Latest activity
2026-10-10
MikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still…
Peak priority
routine
1 routine
Targets
technology
sectors: technology, telco
Sources cited
4
3 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-84411, newest first. Check the date before acting on an older one.

  • Find every RouterOS device whose www or www-ssl service answers from a network you do not trust and upgrade v7 stable devices to 7.24 or later; where the v7 or v6 long-term release is still pending, restrict www and www-ssl under IP > Services to trusted addresses or disable them and manage the router over WinBox, SSH or a VPN.
    2026-10-10CVE-2026-84411

Defender insights

What each entry about CVE-2026-84411 tells a defender to do, newest first.

2026-10-10ROUTINEMikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still pending

Exposure · detection

Story timeline

  1. 2026-10-10CVE-2026-84411, MikroTik RouterOS: one unauthenticated request to the web management service can run code as root; 7.24 fixes the v7 stable channel and the long-term releases are pending (CVSS 3.1 9.8)
    trending-vulnerabilitiesMikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still pending
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-10/cve-2026-84411-mikrotik-routeros-web-management-preauth-rce · ATT&CK page ↗

Entries about MikroTik RouterOS, pre-authentication integer underflow in the web management service (WebFig, www/www-ssl): one crafted request can crash the service or run code as root (CVSS 3.1 9.8); fixed in 7.24 on v7 stable, long-term releases pending (1)

2026-10-10 · view entry permalink →

ROUTINECVE-2026-84411NATOA2

CVE-2026-84411, MikroTik RouterOS: one unauthenticated request to the web management service can run code as root; 7.24 fixes the v7 stable channel and the long-term releases are pending (CVSS 3.1 9.8)

MikroTik's notice of 2026-10-06 describes an integer underflow in HTTP request body handling of the RouterOS web management service, the service behind WebFig on the www and www-ssl ports: a single specially crafted request sent without logging in could crash the service or let an attacker execute code on the router with full privileges, and MikroTik rates the flaw critical as CVE-2026-84411 (MikroTik, 2026-10-06). CISA's advisory ICSA-26-272-06 describes the same flaw as reachable before authentication, scores it CVSS 3.1 9.8 and records no known public exploitation reported to it (CISA, 2026-09-30). RouterOS versions before 7.24, v6 included, are affected on devices where the attacker can reach the web interface; 7.24 fixes the v7 stable channel, while the v7 long-term and v6 long-term releases were still pending when MikroTik wrote (MikroTik, 2026-10-06). BleepingComputer notes that hackers and botnet malware often target MikroTik flaws and recalls a recent CERT Polska warning of an exploit chain against devices with SSH exposed to the internet (BleepingComputer, 2026-09-30).

A single specially crafted HTTP request, sent without logging in, could crash the service or allow an attacker to execute code on the router with full privileges.

Note that in the default configuration the firewall already blocks the web interface from the internet, so a device with default firewall rules is only reachable from the local network.

v7 long-term - release pending

MikroTik

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.

CISA

Builds on: CERT Polska confirms active exploitation of an unauthenticated SSH takeover chain against…

vulnerability10 Oct 03:50Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • cisa.gov2 (50%)
  • bleepingcomputer.com1 (25%)
  • mikrotik.com1 (25%)