CVE-2026-84411 CRITICAL

CVE-2026-84411: MikroTik RouterOS Integer Underflow

Vendor Mikrotik
Product RouterOS
Weakness CWE-191
Published October 2, 2026
Last update October 3, 2026

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

Key dates

02Disclosure timeline

October 2, 2026 CVE published
October 3, 2026 Record updated