MikroTik RouterOS < 7.24 Web Management Integer Underflow RCE (CVE-2026-84411)

critical Nessus Plugin ID 362603

Synopsis

The remote networking device is affected by a remote code execution vulnerability.

Description

According to its self-reported version, the remote networking device is running a version of MikroTik RouterOS prior to 7.24. It is, therefore, affected by a remote code execution vulnerability.

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. (CVE-2026-84411)

Note that Nessus has not tested for this issue but has instead relied only on the router's self-reported version number.

Solution

Upgrade to MikroTik RouterOS 7.24 or later.

See Also

https://mikrotik.com/download

https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06

Plugin Details

Severity: Critical

ID: 362603

File Name: mikrotik_CVE-2026-84411.nasl

Version: 1.1

Type: Remote

Family: Misc.

Published: 10/2/2026

Updated: 10/2/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

CVSS v2

Risk Factor: High

Base Score: 9.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:P

CVSS Score Source: CVE-2026-84411

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros

Required KB Items: MikroTik/RouterOS/Version

Patch Publication Date: 8/14/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-84411

IAVA: 2026-A-1068