2026-10-10ROUTINEMikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still pending
MikroTik RouterOS, pre-authentication integer underflow in the web management service (WebFig, www/www-ssl): one crafted request can crash the service or run code as root (CVSS 3.1 9.8); fixed in 7.24 on v7 stable, long-term releases pending
cve · CVE-2026-84411
Coverage
1
first 2026-10-10 → last 2026-10-10
Latest activity
2026-10-10
MikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still…
Peak priority
routine
1 routine
Targets
technology
sectors: technology, telco
Sources cited
4
3 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-84411, newest first. Check the date before acting on an older one.
- Find every RouterOS device whose www or www-ssl service answers from a network you do not trust and upgrade v7 stable devices to 7.24 or later; where the v7 or v6 long-term release is still pending, restrict www and www-ssl under IP > Services to trusted addresses or disable them and manage the router over WinBox, SSH or a VPN.2026-10-10CVE-2026-84411
Defender insights
What each entry about CVE-2026-84411 tells a defender to do, newest first.
Exposure · detection
Story timeline
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-10/cve-2026-84411-mikrotik-routeros-web-management-preauth-rce · ATT&CK page ↗
Entries about MikroTik RouterOS, pre-authentication integer underflow in the web management service (WebFig, www/www-ssl): one crafted request can crash the service or run code as root (CVSS 3.1 9.8); fixed in 7.24 on v7 stable, long-term releases pending (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- cisa.gov2 (50%)
- bleepingcomputer.com1 (25%)
- mikrotik.com1 (25%)
External references
All cited sources (4)
- mikrotik.comprimaryMikroTik (security notice)https://mikrotik.com/supportsec/cve-2026-84411
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/
- cisa.govCISA (ICSA-26-272-06)https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json