Find notable cyber news and cases, enriched with sources, timelines, and signals.

MikroTik RouterOS pre-auth integer underflow (CVE-2026-84411)

Vulnerability
First reported
Last updated
Happening score
H score 1
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-84411 exposes MikroTik RouterOS management interfaces to unauthenticated root code execution or denial of service through a pre-authentication integer underflow. The affected scope includes RouterOS versions below 7.24. The issue is reachable with a single crafted request.

Related Happenings

CISA MikroTik RouterOS mitigation guidance for CVE-2026-84411

Advisory/Mitigation
H score28 First: 30.09.2026 18:49 Last: 30.09.2026 18:49 Sources 1

How related: CISA's recommendations to MikroTik router owners include the following defensive actions:

About this happening: CISA issued mitigation guidance for MikroTik RouterOS operators affected by CVE-2026-84411, a pre-authentication integer underflow that can enable root code...

MikroTik RouterOS SSH exploitation wave

Exploitation Wave
H score8 First: 06.09.2026 12:32 Last: 06.09.2026 12:32 Sources 1

About this happening: MikroTik RouterOS SSH exploitation is using the MikroTrick chain, where CVE-2026-67279 and CVE-2026-86060 combine to give attackers full administrative control...

Latest development: 23.09.2026 19:06

CERT Polska details the MikroTrick chain on MikroTik RouterOS SSH, combining CVE-2026-67279 with CVE-2026-86060 to let attackers reach full administrative control on Internet-exposed routers without a password or SSH key. Attack logs date to at least September 2, CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, and CERT Polska says some writeups incorrectly included CVE-2026-67276.

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

Timeline

  1. 30.09.2026 18:49 2 articles · 1h ago

    CISA warns of critical pre-authentication flaw in MikroTik RouterOS

    Initial Disclosure

    CISA warned of CVE-2026-84411, a critical pre-authentication integer underflow in MikroTik RouterOS web-management HTTP request handling that can let an unauthenticated network attacker execute code as root or trigger denial of service with a single crafted request. CISA said RouterOS versions below 7.24 are affected and provided defensive guidance to keep control systems off the internet, isolate control networks behind firewalls, and use updated VPNs for remote access.

    Show sources