Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Integer Underflow (CVE‑2026‑84411) Enables Unauthenticated Remote Code Execution in MikroTik RouterOS < 7.24

CISA alerts that MikroTik RouterOS versions before 7.24 contain an integer underflow that can be exploited without authentication to execute arbitrary code as root or cause denial‑of‑service. The CVSS 9.8 flaw affects routers worldwide, including critical communications infrastructure, and must be remediated to keep audit‑ready control over network devices.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Critical Integer Underflow (CVE‑2026‑84411) Enables Unauthenticated Remote Code Execution in MikroTik RouterOS < 7.24

What It Is — A newly disclosed integer underflow (CWE‑191) in the web‑management service of MikroTik RouterOS versions prior to 7.24 allows an unauthenticated attacker to send a crafted HTTP request that triggers arbitrary code execution as root or a denial‑of‑service.

Exploitability — The flaw is reachable without authentication; proof‑of‑concept code has been published and the CVSS v3 base score is 9.8 (Critical). No public exploit‑as‑a‑service is known yet, but the risk of rapid weaponisation is high.

Affected Products — MikroTik RouterOS < 7.24 (all hardware platforms that run the OS).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous firmware inventory and automated patch verification as evidence of due‑diligence.
  • Highlights gaps in configuration‑change control; without a documented remediation workflow, auditors cannot verify that a critical network component is protected.
  • A successful RCE would break the integrity of the communications layer, undermining the control objective of secure device management that many frameworks map to a single VCF control.

Recommended Actions

  • Upgrade every MikroTik device to RouterOS 7.23 or later immediately.
  • Run an inventory scan to confirm the OS version on all routers and capture the version data as audit evidence.
  • Enable network‑based IDS/IPS signatures that detect the crafted HTTP request pattern.
  • Document the remediation in your change‑management system and retain the upgrade logs for future assessments.

Source: CISA Advisory – ICSA‑26‑272‑06

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-06 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →