CVE-2026-56719: MikroTik RouterOS
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Affected products
- MikroTik RouterOS: up to and including 6.49.18; from 7.0.0, up to and including 7.11.2
Published 2026-09-16. Last modified 2026-09-24.