---
schema: 1
kind: vulnerability
title: "CVE-2026-84411, MikroTik RouterOS: one unauthenticated request to the web management service can run code as root; 7.24 fixes the v7 stable channel and the long-term releases are pending (CVSS 3.1 9.8)"
headline: "MikroTik names the fix for a pre-auth RouterOS web-interface RCE; the v7 and v6 long-term releases are still pending"
summary: >
  MikroTik's notice of 2026-10-06 describes CVE-2026-84411, an integer underflow in HTTP request body handling of the RouterOS web
  management service (WebFig, on the www and www-ssl ports) that one crafted request sent without logging in can use to crash the
  service or run code on the router with full privileges; CISA scores it CVSS 3.1 9.8. RouterOS before 7.24, v6 included, is affected
  where an attacker can reach the web interface; 7.24 fixes the v7 stable channel, the v7 and v6 long-term releases are pending, MikroTik says the default
  firewall already blocks the web interface from the internet, and CISA records no known public exploitation.
discovered_at: "2026-10-10T03:50:30Z"
updated_at: null
event_date: "2026-10-06"
run_id: 2026-10-10T0255Z-intel
priority: routine
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, patch-available]
regions: [global]
sectors: [technology, telco]
entities: ["product:mikrotik-routeros"]
techniques: [T1190]
affected_products: ["MikroTik RouterOS"]
cves:
  - id: CVE-2026-84411
    cvss: "9.8 (CVSS 3.1, CISA)"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "RouterOS before 7.24, including v6, on devices where the web interface (www, www-ssl) is reachable by the attacker"
    fixed: "7.24 on the v7 stable channel; v7 long-term and v6 long-term releases pending per MikroTik as of 2026-10-06"
sources:
  - url: "https://mikrotik.com/supportsec/cve-2026-84411"
    publisher: "MikroTik (security notice)"
    date: "2026-10-06"
    role: primary
  - url: "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06"
    publisher: "CISA (ICSA-26-272-06)"
    date: "2026-09-30"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/"
    publisher: "BleepingComputer"
    date: "2026-09-30"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities Catalog"
    date: "2026-10-08"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A single specially crafted HTTP request, sent without logging in, could crash the service or allow an attacker to execute code on the router with full privileges."
    publisher: "MikroTik"
    source_url: "https://mikrotik.com/supportsec/cve-2026-84411"
  - quote: "Note that in the default configuration the firewall already blocks the web interface from the internet, so a device with default firewall rules is only reachable from the local network."
    publisher: "MikroTik"
    source_url: "https://mikrotik.com/supportsec/cve-2026-84411"
  - quote: "v7 long-term - release pending"
    publisher: "MikroTik"
    source_url: "https://mikrotik.com/supportsec/cve-2026-84411"
  - quote: "No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time."
    publisher: "CISA"
    source_url: "https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06"
verification: multi-source
sourcing_note: >
  The affected range, the fixed build and the mitigation come from MikroTik's own notice; CISA's advisory restates the flaw and adds its
  own CVSS 3.1 score and the statement that it knows of no public exploitation.
confidence: high
references:
  - 2026-09-06/mikrotik-routeros-mikrotrick-ssh-auth-bypass-privesc-chain
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Find every RouterOS device whose www or www-ssl service answers from a network you do not trust and upgrade v7 stable devices to 7.24 or later; where the v7 or v6 long-term release is still pending, restrict www and www-ssl under IP > Services to trusted addresses or disable them and manage the router over WinBox, SSH or a VPN."
updates: []
migrated_from: null
---

MikroTik's notice of 2026-10-06 describes an integer underflow in HTTP request body handling of the RouterOS web management service, the service behind WebFig on the www and www-ssl ports: a single specially crafted request sent without logging in could crash the service or let an attacker execute code on the router with full privileges, and MikroTik rates the flaw critical as CVE-2026-84411 ([MikroTik, 2026-10-06](https://mikrotik.com/supportsec/cve-2026-84411)). CISA's advisory ICSA-26-272-06 describes the same flaw as reachable before authentication, scores it CVSS 3.1 9.8 and records no known public exploitation reported to it ([CISA, 2026-09-30](https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06)). RouterOS versions before 7.24, v6 included, are affected on devices where the attacker can reach the web interface; 7.24 fixes the v7 stable channel, while the v7 long-term and v6 long-term releases were still pending when MikroTik wrote ([MikroTik, 2026-10-06](https://mikrotik.com/supportsec/cve-2026-84411)). BleepingComputer notes that hackers and botnet malware often target MikroTik flaws and recalls a recent CERT Polska warning of an exploit chain against devices with SSH exposed to the internet ([BleepingComputer, 2026-09-30](https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/)).

**Exposure:** a RouterOS device on a version before 7.24 whose www or www-ssl service an attacker can reach; the services and their allowed addresses are listed under IP > Services ([MikroTik, 2026-10-06](https://mikrotik.com/supportsec/cve-2026-84411)). MikroTik says a device with default firewall rules is reachable only from the local network, so internet exposure means a device whose firewall or service settings let the web interface through ([MikroTik, 2026-10-06](https://mikrotik.com/supportsec/cve-2026-84411)).

**Detection:** MikroTik and CISA publish no indicators and neither reports exploitation. MikroTik says a single request could crash the service ([MikroTik, 2026-10-06](https://mikrotik.com/supportsec/cve-2026-84411)), so repeated restarts of the web service on a device reachable from untrusted networks are worth checking.

**Defender takeaway:** upgrade v7 stable devices to 7.24 or later; on a long-term or v6 device, for which MikroTik lists no fixed release yet, restrict the web services to trusted addresses or disable them and manage the router over WinBox, SSH or a VPN, as MikroTik advises, and do not open management ports to the internet ([MikroTik, 2026-10-06](https://mikrotik.com/supportsec/cve-2026-84411)). No source reports exploitation as of 2026-10-10, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog (version 2026.10.08) ([CISA KEV catalog, 2026-10-08](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)).
