CVE-2026-93345
CVSS 7.5 HIGH: mikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI… EPSS 0.5% (41st percentile).
Vulnerabilities & Exploits
CVE-2026-84411 affects MikroTik RouterOS versions before 7.24, where an integer underflow in the web management service can let an unauthenticated network attacker run code as root or trigger a denial of service with one crafted request.
The flaw sits in HTTP request-body handling before login checks. In plain terms, a malformed web request can make the router miscount data and process it the wrong way, so the attacker crosses from a normal request into root-level control without credentials.
For operators, the exposure is wherever RouterOS web management is reachable from untrusted networks: the service itself becomes the attack surface, and a single internet-facing admin interface can turn into full-device takeover before passwords or MFA matter.
4 sources · 4h ago
CVSS 7.5 HIGH: mikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI… EPSS 0.5% (41st percentile).
CVE Program records
MikroTik RouterOS Integer Underflow
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication.
originalCSIRT Italia / ACN
Risolta vulnerabilità in MikroTik RouterOS
Aggiornamenti di sicurezza per MikroTik RouterOS sanano una vulnerabilità con gravità "critica".
originalBleepingComputer
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
originalPart of the PlainSec briefing for 2026-10-02
Every edition of this story: MikroTik RouterOS Pre-Auth Bug Hands Out Root