CVE CVE-2026-84411
Severity CRITICAL · CVSS 3.1 9.8 · CVSS 4.0 9.3
Weakness CWE-191
Affected versions < 7.24
Fixed version 7.24
Actively exploited No, as of the date of this article
CISA Advisory ICSA-26-272-06 dated 2026-09-29
Published 2026-10-02

What is the CVE-2026-84411 vulnerability?

The vulnerability consists of an integer underflow (CWE-191) in the handling of HTTP request bodies in the web management service, reachable before authentication. An unauthenticated network attacker can exploit this flaw with a single specially crafted request to achieve arbitrary code execution as the root user or to cause a denial of service.

Which RouterOS versions are vulnerable?

All RouterOS versions lower than 7.24 are vulnerable. The fixed version is 7.24, which is a stable release and not a development version.

Is my router at risk?

Your router is at risk if the web management service (WebFig) is active and reachable from untrusted networks. If you do not use the web service, you must disable it. If you do use it, it must be accessible exclusively from your internal administration network, not from the Internet or from untrusted network segments.

Is the CVE-2026-84411 vulnerability actively exploited?

As of the date of this article, the vulnerability is not listed in the CISA KEV catalog, and ENISA does not report it as being exploited. There is no evidence of active exploitation.

How do I protect my router from CVE-2026-84411?

Updating RouterOS to version 7.24 or later is the primary mitigation recommended by the vendor. While waiting for the update, disable the web management service if it is not necessary, or restrict its access exclusively to the trusted administration network using firewall rules.

Which RouterOS commands are needed to mitigate CVE-2026-84411?

Temporary mitigation: www service

The flaw affects the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the administration network.

# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24

Update RouterOS

The only definitive fix is the update. Save your configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2026-84411 require authentication to be exploited?

No, CVE-2026-84411 is reachable before authentication. An unauthenticated attacker can exploit the vulnerability with a single specially crafted HTTP request.

What is the CVSS score for CVE-2026-84411?

The CVSS v3.1 score assigned by CISA is 9.8 (CRITICAL), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The CVSS v4.0 score is 9.3, also classified as CRITICAL.

Is disabling the web service enough to mitigate CVE-2026-84411?

Yes, disabling the web management service eliminates the attack surface described in CVE-2026-84411, as the flaw resides in the HTTP request handling of that service. However, upgrading to version 7.24 remains the definitive solution recommended by the vendor.

Is CVE-2026-84411 listed in the CISA KEV catalog?

No, CVE-2026-84411 is not listed in the CISA KEV catalog as of the date of this article. The date of addition to the catalog has not been announced.

Official sources