CVE-2026-84411: critical vulnerability in MikroTik RouterOS
MikroTik RouterOS Integer Underflow
Published · Updated
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.3epss 0.9%
exploitation probability
0.9%top 40% of all CVEs
observed exploitation
nono source reports it
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
MikroTik · RouterOSRelated CVEs — MikroTik RouterOS
In the same product, most dangerous first.
CVE-2019-3943—CVE-2019-3943EPSS 3.7%CVE-2023-30800HIGHMikroTik RouterOS Web Interface Heap CorruptionEPSS 1.7%CVE-2023-30799CRITICALMikroTik RouterOS Administrator Privilege EscalationEPSS 1.4%CVE-2025-10948HIGHMikroTik RouterOS libjson.so print parse_json_element buffer overflowEPSS 0.8%CVE-2025-6563MEDIUMCross-site scripting via dst parameter in RouterOS WiFi hotspotEPSS 0.7%CVE-2026-89028HIGHMikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndXEPSS 0.6%