CVE CVE-2026-56719
Severity MEDIUM · CVSS 3.1 6.5 · CVSS 4.0 6.3
Weakness CWE-125
Affected versions <= 6.49.18, <= 7.11.2
Fixed version 7.24.0
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-09-16

What is the CVE-2026-56719 vulnerability?

CVE-2026-56719 is an Out-of-bounds Read weakness (CWE-125) present in the userspace SMB daemon of RouterOS. An unauthenticated attacker can send a minimal SMB1 SessionSetupAndX frame with a specific value for the uniPwdLen field, causing the session handler to read beyond the end of the request buffer. This occurs before any credential validation and could expose sensitive memory contents.

Which RouterOS versions are vulnerable?

The vulnerable versions are all those less than or equal to 6.49.18 and less than or equal to 7.11.2. The fixed version is 7.24.0.

Is my router at risk?

A router is exposed if the SMB file sharing service is active and reachable from untrusted networks. Since the defect is in the SMB server, disabling this service completely eliminates the attack vector for this specific vulnerability.

Is the CVE-2026-56719 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog, and ENISA does not report it as exploited. There is no evidence of active exploitation.

How to protect the router from CVE-2026-56719?

The primary measure is to update RouterOS to version 7.24.0. Alternatively, if the update is not immediate, disabling the SMB service on the router removes the attack surface affected by the defect.

Which RouterOS commands are needed to mitigate CVE-2026-56719?

Temporary mitigation: smb service

The defect concerns the router’s SMB file sharing server, which almost no one uses in production: it should be turned off.

/ip smb print
/ip smb set enabled=no

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2026-56719?

CVE-2026-56719 has a CVSS v3.1 score of 6.5 (MEDIUM) and a CVSS v4.0 score of 6.3 (MEDIUM), both assigned by disclosure@vulncheck.com.

Is authentication required to exploit CVE-2026-56719?

No, CVE-2026-56719 allows an unauthenticated attacker to read sensitive memory by sending a manipulated SMB1 frame before credential validation.

Which RouterOS version fixes CVE-2026-56719?

RouterOS version 7.24.0 fixes CVE-2026-56719, leaving only versions less than or equal to 6.49.18 and 7.11.2 vulnerable.

Is disabling the SMB service enough to mitigate CVE-2026-56719?

Yes, since the vulnerability resides in the SMB daemon, disabling the SMB file sharing service eliminates the exposure to CVE-2026-56719.

Official sources