CVE-2026-39042: Integer Overflow
Published Jul 13, 2026
·Updated
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.
Affected Software
1 affected component
Mikrotik RouterOS>7.21.0<7.21.4, >7.22.0<7.22.2
Event History
Jul 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39042?
CVE-2026-39042 has a high severity score of 7.5 according to the CVSS 3.1 framework.
2
How do I fix CVE-2026-39042?
To fix CVE-2026-39042, upgrade MikroTik RouterOS to version 7.21.4 or higher for 7.21.x and to version 7.22.2 or higher for 7.22.x.
3
What impact does CVE-2026-39042 have?
CVE-2026-39042 allows a remote attacker to cause a denial of service on affected MikroTik RouterOS devices.
4
Which versions of MikroTik RouterOS are affected by CVE-2026-39042?
CVE-2026-39042 affects MikroTik RouterOS versions 7.21.x prior to 7.21.4 and 7.22.x prior to 7.22.2.
5
What type of vulnerability is CVE-2026-39042 classified as?
CVE-2026-39042 is classified as an integer overflow vulnerability.