MikroTik RouterOS pre-auth integer underflow (CVE-2026-84411)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-84411 exposes MikroTik RouterOS management interfaces to unauthenticated root code execution or denial of service through a pre-authentication integer underflow. The affected scope includes RouterOS versions below 7.24. The issue is reachable with a single crafted request.
Related Happenings
CISA MikroTik RouterOS mitigation guidance for CVE-2026-84411
Advisory/Mitigation
H score28
First: 30.09.2026 18:49
Last: 30.09.2026 18:49
Sources 1
How related:
CISA's recommendations to MikroTik router owners include the following defensive actions:
About this happening:
CISA issued mitigation guidance for MikroTik RouterOS operators affected by CVE-2026-84411, a pre-authentication integer underflow that can enable root code...
CISA MikroTik RouterOS mitigation guidance for CVE-2026-84411
Advisory/MitigationHow related: CISA's recommendations to MikroTik router owners include the following defensive actions:
About this happening: CISA issued mitigation guidance for MikroTik RouterOS operators affected by CVE-2026-84411, a pre-authentication integer underflow that can enable root code...
MikroTik RouterOS SSH exploitation wave
Exploitation Wave
H score8
First: 06.09.2026 12:32
Last: 06.09.2026 12:32
Sources 1
About this happening:
MikroTik RouterOS SSH exploitation is using the MikroTrick chain, where CVE-2026-67279 and CVE-2026-86060 combine to give attackers full administrative control...
MikroTik RouterOS SSH exploitation wave
Exploitation WaveAbout this happening: MikroTik RouterOS SSH exploitation is using the MikroTrick chain, where CVE-2026-67279 and CVE-2026-86060 combine to give attackers full administrative control...
Latest development: 23.09.2026 19:06
CERT Polska details the MikroTrick chain on MikroTik RouterOS SSH, combining CVE-2026-67279 with CVE-2026-86060 to let attackers reach full administrative control on Internet-exposed routers without a password or SSH key. Attack logs date to at least September 2, CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, and CERT Polska says some writeups incorrectly included CVE-2026-67276.
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/Mitigation
H score39
First: 30.04.2026 12:24
Last: 30.04.2026 12:24
Sources 1
About this happening:
Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/MitigationAbout this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Timeline
-
30.09.2026 18:49 2 articles · 1h ago
CISA warns of critical pre-authentication flaw in MikroTik RouterOS
Initial DisclosureCISA warned of CVE-2026-84411, a critical pre-authentication integer underflow in MikroTik RouterOS web-management HTTP request handling that can let an unauthenticated network attacker execute code as root or trigger denial of service with a single crafted request. CISA said RouterOS versions below 7.24 are affected and provided defensive guidance to keep control systems off the internet, isolate control networks behind firewalls, and use updated VPNs for remote access.
Show sources
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS — www.bleepingcomputer.com — 30.09.2026 18:49
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS — www.bleepingcomputer.com — 30.09.2026 18:49