CVE-2026-39042
Deferred Deferred - Pending Action

Denial of Service in MikroTik RouterOS

Vulnerability report for CVE-2026-39042, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-14

Assigner: MITRE

Description

An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mikrotik routeros to 7.21.4 (exc)
mikrotik routeros to 7.22.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-39042 is a vulnerability in MikroTik RouterOS versions 7.21.x before 7.21.4 and 7.22.x before 7.22.2. The issue resides in the `unflatten()` function within the `libumsg.so` library. A remote attacker can exploit this flaw to cause a denial of service (DoS) condition on the affected system.

Detection Guidance

Based on the provided context, the vulnerability (CVE-2026-39042) affects MikroTik RouterOS versions 7.21.x before 7.21.4 and 7.22.x before 7.22.2. Detection can be performed by identifying the installed RouterOS version on your MikroTik devices.

  • Check the RouterOS version via the command-line interface (CLI) using the following command: `/system package print`. This will display the installed version.
  • Alternatively, you can check the version via the web interface (WebFig) under 'System' > 'Packages'.

If the installed version falls within the vulnerable ranges (7.21.x before 7.21.4 or 7.22.x before 7.22.2), the system is affected. No specific network-based detection commands or tools are mentioned in the provided context.

Impact Analysis

If you are using an affected version of MikroTik RouterOS, this vulnerability could have the following impacts:

  • Denial of Service (DoS): A remote attacker could exploit this vulnerability to crash or disrupt the normal operation of the router, leading to network downtime or service unavailability.
  • Network Disruption: Since RouterOS is often used in critical network infrastructure, an attack could disrupt connectivity for entire networks or organizations relying on the affected device.
  • Potential for Further Exploitation: While this specific vulnerability is classified as a DoS, it could be used in conjunction with other attacks to compromise network security or stability.
Compliance Impact

This vulnerability could impact compliance with various standards and regulations in the following ways:

  • GDPR (General Data Protection Regulation): If the affected router is part of a network handling personal data of EU citizens, a DoS attack could lead to service disruptions, potentially violating GDPR's requirements for data availability and security (Article 32). Prolonged downtime might also trigger reporting obligations under Article 33.
  • HIPAA (Health Insurance Portability and Accountability Act): For healthcare organizations, network downtime caused by this vulnerability could disrupt access to electronic protected health information (ePHI), violating HIPAA's availability requirements. It may also be considered a security incident requiring risk assessment and potential reporting.
  • PCI DSS (Payment Card Industry Data Security Standard): If the router is part of a cardholder data environment, a DoS attack could disrupt payment processing systems, violating PCI DSS requirements for maintaining secure and available systems (e.g., Requirement 10 on logging and monitoring, or Requirement 12 on maintaining an information security policy).
  • ISO 27001: Organizations certified under ISO 27001 are required to manage information security risks. This vulnerability represents an unmitigated risk that could lead to non-compliance if not addressed promptly, particularly under controls A.12 (Operational security) and A.16 (Information security incident management).
Mitigation Strategies

To mitigate CVE-2026-39042, upgrade your MikroTik RouterOS to a patched version. Specifically, update to:

  • RouterOS 7.21.x: Version 7.21.4 or later
  • RouterOS 7.22.x: Version 7.22.2 or later

These versions address the vulnerability in the unflatten() function of libumsg.so, preventing remote denial-of-service attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39042. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart