Skip to main content

MikroTik RouterOS Pre-Authentication Integer Underflow Allows Root Code Execution With a Single Request (CVE-2026-84411)

Scope: MikroTik RouterOS versions earlier than 7.24

Severity: Red

CISA published advisory ICSA-26-272-06 for CVE-2026-84411 (CVSS 9.8), an integer underflow in how the RouterOS web management service handles HTTP request bodies, reachable before any authentication. A single crafted request can give an attacker code execution with root privileges or crash the device. CISA reported no known exploitation at the time of publication, but the flaw lands only weeks after the MikroTrick chain, which attackers used to take over RouterOS devices without credentials. The version guidance in early reporting was inconsistent, with some sources citing 7.23 and others 7.24, so the safe move is to go straight to the latest stable release, 7.24.4, or the latest long-term release, 7.23.7. MikroTik routers are widely used across Ugandan ISPs, campuses, and small office networks, and they are a regular target for botnet operators. Administrators must update RouterOS immediately through the Check for Updates menu, restrict access to the web management service to trusted management networks only, and make sure it is not reachable from the internet.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.