CISA Warns of Critical Integer Underflow in MikroTik RouterOS
A critical integer underflow vulnerability in MikroTik RouterOS could allow unauthenticated attackers to achieve remote code execution or denial of service.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability affecting MikroTik RouterOS. Identified as CVE-2026-84411, the flaw resides within the device's web management service and poses a significant risk to network security.
The vulnerability is an integer underflow, also known as wrap or wraparound, that exists in the handling of HTTP request bodies. Crucially, this flaw is reachable before any authentication is required, meaning an attacker does not need credentials to exploit it. This characteristic significantly lowers the barrier to entry for malicious actors.
Successful exploitation of CVE-2026-84411 could grant an unauthenticated network attacker the ability to execute arbitrary code with root privileges on the affected device. Alternatively, attackers could leverage the vulnerability to cause a denial-of-service (DoS) condition, disrupting network operations. The severity of this flaw is underscored by its CVSS v3.1 base score of 9.8, classifying it as CRITICAL.
MikroTik RouterOS versions prior to 7.24 are confirmed to be affected by this vulnerability. The company has released version 7.23, which includes a fix for this issue. Users are strongly advised to upgrade to version 7.23 or later as soon as possible to mitigate the risk.
CISA recommends that organizations take defensive measures to minimize the potential impact of this vulnerability. These measures include minimizing network exposure for all control system devices, ensuring they are not directly accessible from the internet, and locating them behind firewalls. When remote access is necessary, secure methods like Virtual Private Networks (VPNs) should be employed, with the caveat that VPNs themselves must be kept updated and secure.
While CISA has not reported any known public exploitation specifically targeting this vulnerability at this time, the critical nature and ease of exploitation warrant immediate attention. The vulnerability was reported to CISA by an anonymous researcher.
This advisory highlights the ongoing challenges in securing network infrastructure devices, particularly those used in critical infrastructure sectors like communications and information technology. The widespread deployment of MikroTik devices globally means that a successful exploit could have far-reaching consequences.
Organizations are encouraged to perform thorough impact analyses and risk assessments before implementing any defensive measures. CISA also provides extensive resources on its website for improving industrial control systems cybersecurity, including best practices for defense-in-depth strategies and targeted cyber intrusion detection and mitigation.