Junglewise Threat Intelligence

CVE-2026-39042: MikroTik RouterOS denial of service in libumsg.so unflatten function

CVE-2026-39042 · Severity: info · CVSS 0 · Published 2026-07-13

Executive brief

A security vulnerability has been identified in MikroTik RouterOS, the operating system used to manage MikroTik networking hardware like routers and switches. A remote attacker can exploit this flaw to crash the device's communication services, leading to a denial of service. This could disrupt network connectivity and management operations for affected organizations.

Technical details

An integer overflow vulnerability exists in the core IPC library (libumsg.so) of MikroTik RouterOS. Specifically, the unflatten() function fails to properly validate input, allowing a remote attacker to trigger a denial of service (DoS) condition. The issue affects RouterOS versions 7.21.x (prior to 7.21.4) and 7.22.x (prior to 7.22.2). Exploitation occurs via the network and results in a crash of the affected service. Patches are available in RouterOS versions 7.21.4 and 7.22.2.

Affected products

  • MikroTik RouterOS 7.21.x before 7.21.4, 7.22.x before 7.22.2

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: disclosed

References

Related threats