Heap Memory Corruption in MikroTik RouterOS Affected by SMB Daemon
CVE-2026-89028

8.2HIGH

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89028?

MikroTik RouterOS versions before 7.24 exhibit a vulnerability within the userspace SMB daemon that allows remote attackers to exploit a heap memory corruption issue. By sending a malicious SMB1 request containing a crafted uniPwdLen value, an attacker may trigger an integer underflow. This exploit uses the flawed value as the copy length in a memory operation, allowing adjacent heap memory to be corrupted. This vulnerability poses a serious risk, as it could enable unauthorized access or manipulation within affected network environments.

Affected Version(s)

RouterOS 0 <= 6.49.18

RouterOS 7.0.0 <= 7.11.2

RouterOS 7.24.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

eeee
VulnCheck
.