SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-39042

HIGH · CVSS 7.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

MikroTik RouterOS versions 7.21.x prior to 7.21.4 and 7.22.x prior to 7.22.2 are vulnerable to a denial of service attack due to an issue in the unflatten() function within libumsg.so, allowing remote attackers to disrupt service. Organizations using affected MikroTik routers should prioritize patching to mitigate the risk of service interruptions. This vulnerability poses a significant threat to network availability and should be addressed promptly by network administrators.

CVE
CVE-2026-39042
Severity
HIGH
CVSS
7.5
EPSS
0.41%

Original NVD Description

An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.