CISA has published ICS Advisory ICSA-26-272-06 covering CVE-2026-84411, a critical vulnerability in MikroTik RouterOS that carries a CVSS v3 score of 9.8 (Critical). The flaw is an integer underflow (wraparound) in the HTTP request body handling of the RouterOS web management service (WebFig/www), and — this is the part that should get your immediate attention — it is reachable before authentication. A successful exploit gives an unauthenticated network attacker remote code execution on the router itself, or the ability to crash the service and cause a denial of service.
All RouterOS versions prior to 7.24 are affected. MikroTik devices are deployed worldwide across the Communications and Information Technology critical infrastructure sectors, and they are a perennial favorite of botnet operators and state-aligned actors precisely because they sit at the network edge, often with their management interfaces under-restricted or — worse — exposed directly to the internet. A pre-auth RCE on the device that routes and filters your traffic is a worst-case scenario: whoever owns the router owns visibility into and control over everything that crosses it.
If you run MikroTik gear anywhere in your environment — CPE, core routing, VPN termination, lab infrastructure — treat this as a drop-everything patching event.
Technical Analysis
Affected Products and Versions
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-84411 |
| CVSS v3 | 9.8 (Critical) |
| Vendor | MikroTik (Riga, Latvia) |
| Product | MikroTik RouterOS |
| Affected Versions | RouterOS < 7.24 |
| Fixed Version | RouterOS 7.24 and later |
| Weakness | CWE-191: Integer Underflow (Wrap or Wraparound) |
| Advisory | CISA ICSA-26-272-06 |
How the Vulnerability Works
The vulnerable component is the web management service (/ip service www — HTTP on TCP/80 by default, and www-ssl on TCP/443). This is the service backing WebFig, RouterOS's browser-based administration interface.
The defect is an integer underflow in HTTP request body handling. In practical terms, when the web service parses a request body, a length or size value is computed with insufficient validation, allowing the value to wrap below zero and underflow to a very large unsigned integer. Memory operations that trust this corrupted length — copies, allocations, bounds checks — then behave catastrophically. From a defender's perspective, the important characteristics are:
- Pre-authentication reachability. The vulnerable parsing code executes while handling the HTTP request, before any credential check. An attacker only needs network reachability to the web management port. No credentials, no session, no user interaction.
- Malformed HTTP request bodies are the delivery vehicle. Exploitation does not require valid WebFig sessions or legitimate API calls — just crafted requests to the service.
- Two outcomes: RCE or DoS. Depending on heap layout and the attacker's payload, the underflow can be shaped into arbitrary code execution in the context of the RouterOS service (which runs with effectively full device privileges), or a straightforward crash that takes down the management plane and potentially the device.
- No user interaction required. This is a fully network-driven attack vector.
Because RouterOS is a closed, monolithic network operating system, successful code execution typically means the attacker can install persistence (RouterOS has a scheduler and scripting engine that attackers routinely abuse), modify firewall/NAT rules, capture or redirect traffic, and use the device as a foothold for pivoting into internal networks. Even the DoS outcome is serious: crashing edge routing gear at an ISP, MSP, or enterprise boundary is an availability event.
Exploitation Status
As of the advisory publication, CISA reports the vulnerability as a publicly disclosed security issue with no confirmed widespread in-the-wild exploitation cited in the advisory text. However, three factors compress the time-to-exploitation window dramatically:
- MikroTik is one of the most-targeted network platforms in the world. Botnet operators and APT groups maintain standing MikroTik exploitation capability.
- Pre-auth RCE against a web service is the easiest class of vulnerability to weaponize. Once a PoC circulates, mass scanning of TCP/80 and TCP/443 against MikroTik fingerprints follows within days.
- The vulnerability class is deterministic. Integer underflows with a reachable parser path are typically highly reproducible, making reliable PoC development straightforward.
Defenders should operate under the assumption that scanning and exploitation attempts are imminent or already occurring against internet-exposed WebFig interfaces.
Detection & Response
Honest framing first: RouterOS is a closed platform — you cannot run an EDR agent on it, and post-exploitation artifacts on the device itself are hard to acquire without forensics-mode access. Your detection strategy therefore rests on three pillars: (1) network telemetry around the management interface, (2) RouterOS syslog forwarded to your SIEM, and (3) hunting endpoint-to-router management traffic from your monitored fleet.
The highest-fidelity signal available to most SOCs is any connection to the RouterOS web management ports from a source that is not a known management host. In a correctly architected environment, WebFig should only ever be reachable from a dedicated management VLAN or jump box. Everything else hitting it is either misconfiguration or attack — and right now, you should assume attack.
Sigma Rules
---
title: Network Connection to MikroTik WebFig Management Interface from Non-Management Host
description: Detects connections to MikroTik RouterOS web management ports (TCP/80, TCP/443 on router interfaces) originating from hosts outside the designated management VLAN/jump hosts. Relevant to CVE-2026-84411 pre-auth exploitation of the WebFig HTTP service. Populate the filter with your authorized management hosts.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
author: Security Arsenal
date: 2026/04/06
id: 8f2c1d94-3a7b-4e51-9c62-7d5e6f8a9012
status: experimental
tags:
- attack.initial_access
- attack.t1190
- attack.exploitation
- attack.t1068
logsource:
category: network_connection
product: windows
detection:
selection:
DestinationPort:
- 80
- 443
DestinationIp|cidr:
- '10.0.0.0/24' # TODO: replace with your MikroTik management interface subnet(s)
filter_mgmt_hosts:
SourceIp|cidr:
- '10.255.0.0/28' # TODO: replace with your management VLAN / jump host range
condition: selection and not filter_mgmt_hosts
falsepositives:
- Misconfigured hosts attempting to reach the router's admin UI
- Vulnerability scanners (should be allow-listed separately)
level: high
---
title: MikroTik RouterOS Web Service Crash or Unexpected Reboot via Syslog
description: Detects RouterOS syslog events indicating the www service crashed, the router rebooted unexpectedly, or critical service failures — consistent with denial-of-service exploitation of CVE-2026-84411 integer underflow in HTTP request body handling. Tune the message patterns against your RouterOS logging profile.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
author: Security Arsenal
date: 2026/04/06
id: 3b9e5a17-6c4d-4f28-b183-2a9c4e7d5036
status: experimental
tags:
- attack.impact
- attack.t1499
logsource:
product: routeros
service: syslog
detection:
selection:
message|contains:
- 'www' # web service context in RouterOS log topics
selection_impact:
message|contains:
- 'crashed'
- 'unexpected'
- 'reboot'
- 'kernel failure'
- 'out of memory'
condition: selection and selection_impact
falsepositives:
- Legitimate administrator-initiated reboots during maintenance windows
- Power events on unstable sites
level: medium
---
title: Suspicious Process or Script Execution on Linux Host After MikroTik Management Interaction
description: Detects shell or script interpreter execution spawned by download tools on internal hosts shortly after interaction with network device management — a common pattern when a compromised MikroTik device is used to deliver payloads or when an attacker stages tooling. Focus on wget/curl chains executing retrieved content.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06
author: Security Arsenal
date: 2026/04/06
id: 61d4c8a2-9f30-4b7e-a526-8c1d3e9f7045
status: experimental
tags:
- attack.execution
- attack.t1059
- attack.command_and_control
- attack.t1105
logsource:
category: process_creation
product: linux
detection:
selection_download:
Image|endswith:
- '/wget'
- '/curl'
selection_exec:
CommandLine|contains:
- '| sh'
- '| bash'
- 'chmod +x'
- '/tmp/'
condition: all of selection_*
falsepositives:
- Legitimate software installation scripts executed by administrators
level: medium
The first rule is the one that matters most. If your management-plane segmentation is sound, its false positive rate will be near zero — and any hit is worth paging on. Replace the placeholder CIDRs before deploying, and extend DestinationIp to cover every MikroTik interface address in your inventory, not just the primary management subnet.
KQL (Microsoft Sentinel)
This hunt assumes you are forwarding RouterOS syslog (and ideally firewall logs) to Sentinel via a syslog/CEF collector, and that your network devices are inventoried. It surfaces any non-management source communicating with MikroTik web management ports, plus crash/reboot indicators from device logs.
// Hunt: Unauthorized access attempts to MikroTik WebFig (CVE-2026-84411 exposure)
// Requires: RouterOS syslog forwarded via CEF/Syslog; adjust subnets to your environment.
let MgmtSources = dynamic(["10.255.0.10", "10.255.0.11"]); // Authorized jump hosts / NMS
let MikroTikDevices = dynamic(["10.0.0.1", "10.0.0.2", "192.168.88.1"]); // MikroTik interface IPs
let WebPorts = dynamic([80, 443]);
union isfuzzy=true
(CommonSecurityLog
| where DestinationIP in (MikroTikDevices)
| where DestinationPort in (WebPorts)
| where not(SourceIP in (MgmtSources))
| project TimeGenerated, SourceIP, SourcePort, DestinationIP, DestinationPort, Protocol, DeviceVendor, Message),
(Syslog
| where SyslogMessage has_any ("www", "www-ssl")
| where SyslogMessage has_any ("crashed", "rebooted", "unexpected", "kernel failure", "out of memory")
| project TimeGenerated, HostName, Facility, SeverityLevel, SyslogMessage)
| order by TimeGenerated desc
A second, higher-signal variant hunts for repeated short-lived connections or anomalous request volume to the web service — characteristic of PoC attempts crashing and restarting the service during exploit development or scanning:
// Hunt: Burst traffic pattern against MikroTik web management ports
let MikroTikDevices = dynamic(["10.0.0.1", "10.0.0.2", "192.168.88.1"]);
CommonSecurityLog
| where DestinationIP in (MikroTikDevices)
| where DestinationPort in (80, 443)
| summarize ConnectionCount = count(), DistinctSources = dcount(SourceIP) by DestinationIP, DestinationPort, bin(TimeGenerated, 5m)
| where ConnectionCount > 50
| order by TimeGenerated desc
Velociraptor VQL
RouterOS itself cannot host the Velociraptor agent, so use VQL on your endpoints and servers to hunt for systems that have been talking to MikroTik management interfaces — both to find the source of suspicious management-plane traffic flagged by the network detections above, and to identify potential attacker footholds being used to reach your routers.
-- Hunt: Identify endpoints with active/recent connections to MikroTik web management ports
-- Scope: run across servers and admin workstations; adjust target IPs to your MikroTik inventory.
LET mikrotik_targets = '10.0.0.1|10.0.0.2|192.168.88.1'
SELECT Pid,
Name,
CommandLine,
Username,
netstat().LocalAddr AS LocalAddr,
netstat().LocalPort AS LocalPort,
netstat().RemoteAddr AS RemoteAddr,
netstat().RemotePort AS RemotePort,
netstat().Status AS ConnStatus
FROM pslist()
WHERE netstat().RemotePort in (80, 443)
AND netstat().RemoteAddr =~ mikrotik_targets
Any non-browser, non-monitoring-tool process in these results — especially scripting interpreters, LOLBins, or unknown binaries — warrants immediate triage. Correlate the PID and user against your EDR timeline for the window in question.
Remediation and Verification Script
The following Bash script connects to MikroTik devices over SSH, verifies the RouterOS version, disables the web management services as an immediate compensating control, restricts management access to a defined address list, and reports patch status. Adapt the device list and management CIDR before use. Test on one device before fleet rollout.
#!/bin/bash
# CVE-2026-84411 — MikroTik RouterOS verification & hardening script
# Requires: sshpass (or use key auth), SSH access enabled on target devices.
# Usage: ./mikrotik_cve-2026-84411.sh
DEVICES="mikrotik_devices.txt" # One IP per line
SSH_USER="readonly-audit" # Use a dedicated least-privilege account
MGMT_CIDR="10.255.0.0/28" # Your management VLAN / jump host range
FIXED_MAJOR=7
FIXED_MINOR=24
while read -r HOST; do
echo "=================================================="
echo "[+] Auditing $HOST"
VERSION=$(ssh -o StrictHostKeyChecking=accept-new -o ConnectTimeout=10 \
"${SSH_USER}@${HOST}" "/system resource print" 2>/dev/null | grep -oP 'version: \K[0-9]+\.[0-9]+(\.[0-9]+)?')
if [ -z "$VERSION" ]; then
echo " [!] Could not retrieve version — check connectivity/credentials"
continue
fi
echo " [i] RouterOS version: $VERSION"
MAJOR=$(echo "$VERSION" | cut -d. -f1)
MINOR=$(echo "$VERSION" | cut -d. -f2)
if [ "$MAJOR" -lt "$FIXED_MAJOR" ] || { [ "$MAJOR" -eq "$FIXED_MAJOR" ] && [ "$MINOR" -lt "$FIXED_MINOR" ]; }; then
echo " [VULNERABLE] $HOST is running $VERSION (< ${FIXED_MAJOR}.${FIXED_MINOR}) — CVE-2026-84411 EXPOSED"
# Compensating control 1: disable web management services entirely
ssh "${SSH_USER}@${HOST}" "/ip service set www disabled=yes; /ip service set www-ssl disabled=yes" 2>/dev/null
echo " [+] Disabled www and www-ssl services on $HOST"
# Compensating control 2: restrict remaining management services to mgmt CIDR
ssh "${SSH_USER}@${HOST}" "/ip service set ssh address=${MGMT_CIDR}; /ip service set winbox address=${MGMT_CIDR}; /ip service set api disabled=yes; /ip service set api-ssl disabled=yes" 2>/dev/null
echo " [+] Restricted ssh/winbox to ${MGMT_CIDR}; disabled api/api-ssl on $HOST"
else
echo " [OK] $HOST is patched ($VERSION >= ${FIXED_MAJOR}.${FIXED_MINOR})"
fi
done < "$DEVICES"
echo "=================================================="
echo "Audit complete. Upgrade vulnerable devices to RouterOS 7.24+ immediately."
Note: disabling the www service kills WebFig but not Winbox or SSH — verify your operational workflows first. For devices that legitimately require WebFig, restrict the service with /ip service set www address=<mgmt-CIDR> instead of disabling it.
Remediation
1. Patch — This Is the Only Complete Fix
- Upgrade all MikroTik devices to RouterOS 7.24 or later immediately. Download packages only from the official MikroTik site (mikrotik.com/download) and verify checksums.
- Do not forget RouterBOOT: after upgrading RouterOS, run
/system routerboard upgradeand reboot so the bootloader matches. - Prioritization order: (a) any device with a management interface reachable from the internet or untrusted networks, (b) edge/BGP/VPN termination devices, (c) internal infrastructure, (d) lab gear.
2. Compensating Controls (Apply Today, Even Before Patching)
- Disable the web management service wherever it is not operationally required:
/ip service set www disabled=yesand/ip service set www-ssl disabled=yes. This removes the vulnerable attack surface entirely. - Where WebFig must stay enabled, bind it to an explicit management address list:
/ip service set www address=10.255.0.0/28. Never leave it at the default0.0.0.0/0. - Verify no MikroTik management interface is internet-exposed. Query Shodan/Censys for your netblocks (
port:80 mikrotik,port:8291), and check your external attack surface management tooling. Any exposure found should be treated as an incident, not a finding. - Enforce management-plane segmentation: routers should only be administrable from a dedicated management VLAN or jump host, enforced by both RouterOS service ACLs and upstream firewall policy.
3. Post-Patch Verification and Forensic Triage
- After upgrading, confirm the version with
/system resource printand re-verify that service ACLs survived the upgrade. - For any device whose web management port was exposed to untrusted networks before patching, assume possible compromise: review
/system schedulerand/system scriptfor unauthorized entries (a classic MikroTik persistence mechanism), audit/ip firewalland NAT rules for unexpected changes, review user accounts (/user print), and check for unfamiliar files in the file store. If anything is anomalous, a full factory reset and clean config rebuild is the only defensible remediation — netinstall if you suspect deep persistence. - Enable syslog forwarding from all RouterOS devices to your SIEM (
/system logging action) if you have not already; you cannot detect what you do not collect.
4. Longer-Term Hardening
- Treat network infrastructure with the same patch-management rigor as endpoints: RouterOS belongs in your vulnerability management program with defined SLAs, not in a spreadsheet someone updates quarterly.
- Maintain an accurate MikroTik inventory — shadow MikroTik gear (branch routers, ISP-provided CPE, lab boxes) is consistently where these devices get forgotten.
- Review the CISA ICSA-26-272-06 advisory and MikroTik's release notes for 7.24 for any additional guidance.
A 9.8 pre-auth RCE on the world's most-abused SOHO/SMB routing platform will not stay unexploited for long. Patch to 7.24, kill the web service where you can, and check your exposure now — before someone else does.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.