CVE CVE-2026-39042
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-190
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-07-13

What is the CVE-2026-39042 vulnerability?

The vulnerability consists of an Integer Overflow or Wraparound in the unflatten() function within the libumsg.so library. A remote attacker can exploit this flaw to cause a denial of service on the device.

Which RouterOS versions are vulnerable?

Versions 7.21.x prior to v.7.21.4 and versions 7.22.x prior to v.7.22.2 are vulnerable. The fixed versions are v.7.21.4 and v.7.22.2.

Is my router at risk?

A router is exposed if it is running one of the listed vulnerable versions and is reachable from untrusted networks. There is no indication that a specific RouterOS service is exclusively involved, but the vulnerability resides in the IPC communication library (libumsg.so) used by the system.

Is the CVE-2026-39042 vulnerability actively exploited?

As of the date of the article, there is no evidence that the vulnerability is being actively exploited. It is not present in the CISA KEV catalog, and ENISA does not report it as exploited.

How to protect the router from CVE-2026-39042?

The only effective mitigation is updating the firmware to versions v.7.21.4 or v.7.22.2, depending on the installed version series. No alternative mitigations have been communicated by the vendor.

Which RouterOS commands are needed to mitigate CVE-2026-39042?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2026-39042?

The CVSS v3.1 score assigned to CVE-2026-39042 is 7.5, with HIGH severity. The vector indicates a remote attack with low complexity, no authentication or user interaction required, impacting only the availability of the system.

Which versions fix CVE-2026-39042?

The versions that fix CVE-2026-39042 are v.7.21.4 for the 7.21.x series and v.7.22.2 for the 7.22.x series.

Does CVE-2026-39042 require authentication to be exploited?

No, CVE-2026-39042 does not require authentication. The CVSS vector indicates PR:N (Privileges Required: None), meaning a remote attacker can exploit the vulnerability without credentials.

What is the underlying weakness (CWE) of CVE-2026-39042?

The underlying weakness of CVE-2026-39042 is CWE-190, defined as Integer Overflow or Wraparound.

Official sources