
What is CVE-2026-84411?
CVE-2026-84411 is an integer underflow in the web management service of MikroTik RouterOS, classified as CWE-191. The flaw sits in the service’s HTTP request body handling and is reachable before authentication. A single crafted request lets an unauthenticated network attacker execute arbitrary code as root, or crash the device.
The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required. Confidentiality, integrity, and availability impacts are all rated high.
Exploitation is pre-authentication and requires no chaining. The attacker needs only network reachability to the web management service, which listens on TCP/80 for www and TCP/443 for www-ssl. There is no credential, no session, and no second stage. Code execution lands as root, which on RouterOS means full control of the routing and firewall configuration rather than control of a single application.
CISA published the issue as an ICS advisory on October 2, 2026, which reflects how heavily RouterOS is deployed in telecommunications, internet service provider, and utility networks. Neither CISA nor MikroTik has reported confirmed exploitation in the wild at the time of writing, and no public proof of concept has been confirmed. That gap is unlikely to be durable. The vulnerability class is deterministic, the affected service is trivially fingerprinted at internet scale, and the precondition is a default-enabled management interface.
What assets are affected by CVE-2026-84411?
Every RouterOS version below 7.24 is affected. MikroTik fixed the flaw in 7.24, and the advisory draws no distinction between the long-term and stable branches: the 6.x line is affected in full alongside 7.x releases up to 7.23.x.
In practice an affected asset is a MikroTik router, switch, or wireless access point with WebFig reachable from the internet. The www and www-ssl services are enabled by default, so exposure follows from a device being internet-facing rather than from any deliberate configuration choice. These devices sit at branch offices, retail sites, hotel and venue networks, remote industrial locations, and in service provider access networks, which is precisely where RouterOS is chosen for its price and capability.
Two deployment realities widen the exposure. MikroTik hardware is frequently installed by a local integrator or a regional ISP rather than by the organization’s own network team, so the devices often sit outside central asset inventory and outside the patch cycle that covers servers and endpoints. RouterOS upgrades are also a manual, per-device operation that requires a reboot, which means fleets drift for years.
Unlike most emerging threats, the affected population here is determinable from the outside. RouterOS advertises its version on several services, so an external scan can tell an affected device from a patched one without access to the device. That cuts both ways: it makes defender inventory straightforward, and it makes attacker targeting equally straightforward.
What does our data show about exposure patterns?

Exposure in this set is led by Consumer Discretionary at 47.1% of observed assets, with Industrials contributing 20.4% and Consumer Staples 9.6%. The remaining sectors together account for 22.9%.
That leading share reflects estate size rather than any sector characteristic. Exposure here is heavily concentrated: individual large estates account for a substantial share of the observed assets, and the largest of them sits in Consumer Discretionary.
The underlying pattern is about operating model, not industry. Organizations that run many small physical sites, hotels, depots, branches, plants, and retail locations, buy inexpensive routing hardware per site and accumulate large fleets of it. Hospitality, logistics, and consumer brands fit that shape, and so do the industrial and consumer staples businesses behind the next two bars.
This dataset differs from most in one important respect. Roughly two fifths of the observed assets carry a confirmed RouterOS version rather than a service fingerprint alone, because the devices advertise their version. Every single version identified in the set falls below 7.24. Not one patched device appears.
That makes this a far firmer finding than the usual “potentially affected” population. For the version-identified portion, the question is not whether the software is in the affected range but whether the web management service is reachable from an untrusted network. The remaining assets, identified by fingerprint without a version, sit in the usual grey area and need a direct check.
The geographic spread is the last signal worth noting. The assets in this set resolve across a wide span of countries, many of them places where an organization has a local site rather than a datacenter. That is the shape of infrastructure bought locally and managed loosely, and it is the hardest kind to patch on a deadline.
Are fixes available?
Yes. MikroTik fixed the issue in RouterOS 7.24, available from the vendor download page. Any device below that version should be upgraded, and on RouterBOARD hardware the bootloader should be upgraded alongside the operating system with /system routerboard upgrade so the firmware and RouterOS stay in step.
Devices on the 6.x line face a larger decision. There is no 6.x fix, so remediation means a major-version migration to 7.x with the configuration review that implies, and some older hardware will not carry a current RouterOS build at all. For those devices the practical options are replacement or removing the web management service from the internet entirely.
MikroTik does not operate these devices, and in many cases neither does the organization that depends on them. Where an integrator or ISP manages the hardware, the upgrade has to be requested and then verified rather than assumed. Defenders should confirm the running version per device after the change rather than relying on a ticket being closed.
Are there any other recommended actions to take?
Until patching is confirmed, defenders should:
- Inventory every internet-facing MikroTik device, including integrator-managed and branch hardware
- Disable the web management service with
/ip service set www disabled=yes - Disable the TLS variant with
/ip service set www-ssl disabled=yes - Bind WebFig to a management subnet where the interface must stay available
- Block
TCP/80andTCP/443to device management addresses at the network edge - Audit
/system schedulerand/system scripton previously exposed devices for unauthorized entries - Review device user accounts and firewall rules for changes nobody on the team made
How can CyCognito help your organization?
CyCognito published an Emerging Threat Advisory for CVE-2026-84411 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.
To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.