Someone left the master key under the welcome mat, and the mat is visible from space
CVE-2026-84411 is an integer underflow (CWE-191) in the HTTP request body handler of MikroTik RouterOS's web management service (WebFig). The flaw fires *before* any authentication check, meaning an unauthenticated remote attacker can send a single crafted HTTP request to achieve arbitrary code execution as root — or crash the device outright. Affected versions include the entire RouterOS 7.x line prior to 7.24 and the 6.x line prior to 6.49.21. MikroTik has released patches in 7.24.2, 7.23.4, and 6.49.21. CISA published advisory ICSA-26-272-06 on September 29, 2026.
CISA scored this at CVSS 9.8 and that score is dead-on. There is zero friction in the exploit chain once the web management interface is reachable: no credentials, no user interaction, no complex race condition, no chaining required. MikroTik routers are *network edge appliances by definition* — every single installation sits at a network boundary. Historically, Shodan has indexed between 500,000 and 900,000 internet-facing RouterOS instances, many with web management enabled by default. The blast radius of root on a border router is total: traffic interception, DNS hijacking, VPN tunnelling into the internal network, and pivot to every host behind it. This is not an overhyped desktop vuln; this is a one-shot network takeover.
4 steps from start to impact.
Identify exposed WebFig service
MikroTik HttpProxy or the RouterOS login page fingerprint return hundreds of thousands of results. No credentials or interaction is needed for discovery.- Target MikroTik device has WebFig enabled and reachable from attacker's network position
- Some enterprises restrict web management to internal/VPN-only — but MikroTik defaults to allowing it on all interfaces
- ISP and SOHO deployments overwhelmingly leave it exposed
Send crafted HTTP request triggering integer underflow
- Network connectivity to WebFig port
- Knowledge of the integer underflow trigger (specific malformed HTTP request)
- No public PoC exists as of September 30, 2026 — but the vulnerability class (integer underflow in HTTP parsing) is well-understood and the advisory provides enough detail for skilled researchers to reproduce
- MikroTik's proprietary OS makes reverse engineering slightly harder than open-source targets
Achieve arbitrary code execution as root
root privileges. RouterOS runs on a minimal Linux-derived kernel with limited ASLR and no modern exploit mitigations like CFI. Root on RouterOS means full control of the device's routing table, firewall rules, VPN configurations, and DNS settings.- Successful memory corruption from Step 2
- RouterOS is a proprietary embedded OS — exploit development requires device-specific knowledge
- No public weaponized exploit yet
Establish persistence and pivot
- Root access achieved in Step 3
- None — once root is achieved, the device is fully controlled
/user print), unexpected scripts (/system script print), altered DNS settings (/ip dns print), or new VPN/tunnel interfaces; Shadowserver and GreyNoise honeypots may flag scanning from compromised device IPs/ip service set www address=<mgmt-subnet> and /ip service set www-ssl address=<mgmt-subnet> to bind the HTTP(S) management interface to a trusted management VLAN or specific IP range. This eliminates the remote attack vector entirely. If web management is not needed, disable it: /ip service disable www and /ip service disable www-ssl. Deploy within 3 days per the noisgate mitigation SLA for CRITICAL./ip firewall filter add chain=input src-address=!<mgmt-subnet> dst-port=80,443,8080,8291,22 protocol=tcp action=drop. This provides defense-in-depth even if service-level ACLs are misconfigured. Deploy within 3 days./user print), unknown scripts (/system script print), altered DNS (/ip dns print), rogue VPN interfaces, or log entries showing 'user added by' from unknown IPs. The MikroTrick SSH chain is already being exploited in the wild and patches overlap. Deploy immediately.- WAF in front of MikroTik — MikroTik routers are themselves the network edge; there is typically no WAF sitting in front of the router's management interface. Deploying a reverse proxy in front of a router's admin panel is architecturally impractical.
- MFA on WebFig — The vulnerability is pre-authentication. MFA or strong passwords are irrelevant because the exploit fires before any credential check occurs.
- RouterOS firewall on the device itself — If the firewall rules allow HTTP management access (which they must for WebFig to function), the vulnerable code path is reached before the firewall can help. The firewall only helps if it blocks management port access entirely from untrusted sources (which is listed as a compensating control above).
- Firmware integrity monitoring — RouterOS does not support runtime integrity monitoring or file-integrity checking tools. There is no equivalent of AIDE or Tripwire available on the platform.
The supporting signals.
| In-the-Wild Exploitation | Not yet observed for CVE-2026-84411 specifically. However, the related MikroTrick SSH chain (CVE-2026-67276 + CVE-2026-86060) has been actively exploited since September 2, 2026 per CERT Polska, demonstrating strong attacker interest in RouterOS targets. |
|---|---|
| Proof-of-Concept | No public PoC as of September 30, 2026. No entries found on pocindex.io, ExploitDB, or GitHub repos named after the CVE. The vulnerability class (integer underflow in HTTP parser) is straightforward to reproduce given the advisory detail — expect weaponization within days to weeks. |
| EPSS Score | Not yet scored — CVE-2026-84411 was published September 29, 2026 and has not entered the FIRST EPSS model yet. Given the pre-auth/network/RCE profile, expect a high EPSS score (>0.90) once scored. |
| KEV Status | Not listed in CISA Known Exploited Vulnerabilities catalog as of September 30, 2026. Given CISA published the ICS advisory (ICSA-26-272-06) directly, KEV addition is likely if exploitation is confirmed. |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — 9.8 CRITICAL. Every base metric is at maximum severity. The v4.0 vector scores 9.3. This is the textbook worst-case network attack profile: no privileges, no interaction, full CIA impact. |
| Affected Versions | RouterOS 7.0 through 7.24.1 (v7 branch) and 6.0 through 6.49.20 (v6 branch). Virtually all RouterOS deployments running any version prior to the September 2026 patches are vulnerable. |
| Fixed Versions | RouterOS 7.24.2 (stable), 7.23.4 (LTS backport), 6.49.21 (v6 LTS backport), 7.25beta3 (beta). Available at mikrotik.com/download. |
| Internet Exposure | Shodan historically indexes 500,000–900,000 internet-facing MikroTik RouterOS instances. Shadowserver identified ~122,500 with SSH exposed as of September 5, 2026. WebFig (HTTP) exposure is estimated at a comparable or higher scale given default-on behavior. Per Enlyft, MikroTik holds ~7% networking hardware market share with 9,000+ tracked enterprise customers. |
| Disclosure & Advisory | CISA published advisory ICSA-26-272-06 on September 29, 2026. MikroTik published a support security page for September 2026 vulnerabilities. Reporter listed as anonymous researcher. |
| Historical Context | MikroTik RouterOS has a pattern of critical pre-auth vulns: CVE-2018-14847 (Winbox credential leak, used by Mēris botnet), CVE-2023-30799 (privilege escalation, 500K+ exposed). APT28/Fancy Bear has used compromised MikroTik routers for DNS hijacking campaigns. Attacker tooling and knowledge of RouterOS internals is mature. |
Sources.
- CISA ICS Advisory ICSA-26-272-06
- SecurityOnline — Critical MikroTik RouterOS Flaw CVE-2026-84411
- MikroTik September 2026 Security Advisory
- CERT Polska — MikroTik RouterOS Actively Exploited
- The Hacker News — Attackers Hijack MikroTik Routers
- Insomnisec — MikroTrick Analysis
- MikroTik Router Statistics 2026 — Layer-x
- MikroTik Market Share — Enlyft
Why this verdict
- Pre-auth, single-request RCE as root: The attack chain has zero authentication friction. No credentials, no user interaction, no multi-step chaining. A single malformed HTTP request yields root. This is the lowest-friction attack profile possible.
- Canonical network edge appliance — verdict floor is CRITICAL: MikroTik RouterOS runs exclusively on routers and network appliances. 100% of installations occupy the high-value 'network edge appliance' role by definition. Root on a border router gives the attacker traffic interception, DNS hijacking, VPN tunnelling, and a direct pivot to every host on the internal network. The blast radius is fleet-scale.
- Role multiplier: (a) *Low-value role*: Does not exist — no one runs RouterOS on a workstation or sandbox. (b) *Typical role*: Branch office or SOHO router — compromise gives full control of that site's network traffic and a lateral pivot point. (c) *High-value role*: ISP edge router, enterprise perimeter gateway, ICS/OT network gateway — compromise gives mass traffic interception across thousands of downstream customers, or direct access to OT networks. ≥10% of MikroTik installs serve ISP or enterprise edge roles. The chain succeeds identically in all roles (pre-auth, no config dependency beyond WebFig reachability). Blast radius at the high-value role is fleet-to-supply-chain scale.
- Massive internet-facing attack surface: 500,000–900,000 RouterOS instances historically visible on Shodan. WebFig is enabled by default on all interfaces. The exposed population dwarfs most CVEs.
- Active attacker interest in MikroTik: The MikroTrick SSH chain (CVE-2026-67276/CVE-2026-86060) is already being actively exploited as of September 2, 2026. Threat actors are actively scanning for and compromising MikroTik devices right now. CVE-2026-84411 provides an even easier path (HTTP vs SSH, pre-auth vs auth-bypass). Weaponization pressure is extreme.
- Immature exploit mitigations on RouterOS: RouterOS runs on a minimal Linux-derived kernel with limited ASLR, no CFI, no stack canaries on many code paths, and no EDR/endpoint protection. Memory corruption exploitation is significantly easier than on modern desktop or server operating systems.
Why not higher?
There is no severity above CRITICAL. A CVSS 9.8 with pre-auth network RCE on a canonical network edge appliance is the ceiling of the severity scale.
Why not lower?
Downgrading below CRITICAL would require evidence that the exposed population is negligible (<1% of installs with WebFig reachable) or that the exploit chain has significant practical friction. Neither is true. WebFig is on by default, hundreds of thousands of devices are internet-facing, the chain is a single unauthenticated request, and the target platform lacks modern exploit mitigations. The temporary absence of a public PoC does not justify a downgrade — the vulnerability class is well-understood and the advisory detail is sufficient for rapid reproduction.
Crowdsourced verification payload.
Run this script from an auditor workstation with SSH access to the target MikroTik device. Invoke as: bash check_cve_2026_84411.sh <router-ip> [ssh-user]. Requires SSH client and valid credentials for the target device. The script checks the RouterOS version and reports whether the device is vulnerable.
#!/usr/bin/env bash
# check_cve_2026_84411.sh — MikroTik RouterOS CVE-2026-84411 checker
# Usage: bash check_cve_2026_84411.sh <router-ip> [ssh-user]
# Exit codes: 1=VULNERABLE, 0=PATCHED, 2=UNKNOWN
set -euo pipefail
HOST="${1:?Usage: $0 <router-ip> [ssh-user]}"
USER="${2:-admin}"
echo "[*] Checking MikroTik RouterOS version on $HOST as $USER..."
# Grab version string via SSH
VERSION_RAW=$(ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=accept-new "${USER}@${HOST}" \
'/system resource print' 2>/dev/null | grep -i 'version:' | head -1) || {
echo "UNKNOWN — could not connect to $HOST via SSH"
exit 2
}
VERSION=$(echo "$VERSION_RAW" | sed -E 's/.*version:[[:space:]]*//' | sed -E 's/[[:space:]].*//' | tr -d '\r')
if [ -z "$VERSION" ]; then
echo "UNKNOWN — could not parse RouterOS version from output"
exit 2
fi
echo "[*] Detected RouterOS version: $VERSION"
# Parse major.minor.patch
MAJOR=$(echo "$VERSION" | cut -d. -f1)
MINOR=$(echo "$VERSION" | cut -d. -f2)
PATCH=$(echo "$VERSION" | cut -d. -f3)
PATCH=${PATCH:-0}
# Check if WebFig is enabled
WEBFIG=$(ssh -o ConnectTimeout=10 "${USER}@${HOST}" \
'/ip service print where name=www' 2>/dev/null | grep -c 'disabled.*no') || WEBFIG=0
if [ "$WEBFIG" -gt 0 ]; then
echo "[!] WebFig (HTTP) is ENABLED on this device"
else
echo "[*] WebFig (HTTP) appears disabled (reduced exposure)"
fi
# Version comparison logic
# Fixed versions: 7.24.2, 7.23.4, 6.49.21
vulnerable=0
if [ "$MAJOR" -eq 7 ]; then
if [ "$MINOR" -ge 25 ]; then
vulnerable=0 # 7.25+ is safe
elif [ "$MINOR" -eq 24 ] && [ "$PATCH" -ge 2 ]; then
vulnerable=0 # 7.24.2+ is safe
elif [ "$MINOR" -eq 23 ] && [ "$PATCH" -ge 4 ]; then
vulnerable=0 # 7.23.4+ is safe
else
vulnerable=1
fi
elif [ "$MAJOR" -eq 6 ]; then
if [ "$MINOR" -gt 49 ]; then
vulnerable=0
elif [ "$MINOR" -eq 49 ] && [ "$PATCH" -ge 21 ]; then
vulnerable=0 # 6.49.21+ is safe
else
vulnerable=1
fi
else
echo "UNKNOWN — unexpected major version $MAJOR"
exit 2
fi
if [ "$vulnerable" -eq 1 ]; then
echo "VULNERABLE — RouterOS $VERSION is affected by CVE-2026-84411"
echo " Fix: Update to 7.24.2 / 7.23.4 / 6.49.21"
echo " Immediate mitigation: Restrict or disable WebFig access"
exit 1
else
echo "PATCHED — RouterOS $VERSION is not affected by CVE-2026-84411"
exit 0
fi