CVE-2026-56719: MikroTik RouterOS

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.

Affected products

  • MikroTik RouterOS: up to and including 6.49.18; from 7.0.0, up to and including 7.11.2

Published 2026-09-16. Last modified 2026-09-24.