Status: UPDATED
| Advisory ID: CVE-2026-84411
Key Details
| CVE | CVE-2026-84411 |
| CVSS Score / Version | 9.8 (Critical) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | MikroTik RouterOS |
| Classified as | CWE-191 (Integer Underflow (Wrap or Wraparound)) |
Affected Products, Subsystems & Sectors
| Subsystems | Industrial Network - Routers/Firewalls |
| Sectors | Multi-sector |
What to Know
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. (NVD)
What to Do
Monitor MikroTik's web page for any future patch releases.
References