| CVE | CVE-2026-89028 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 · CVSS 4.0 8.2 |
| Weakness | CWE-122, CWE-191 |
| Affected versions | <= 6.49.18, <= 7.11.2 |
| Fixed version | 7.24.0 |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2026-09-16 |
What is the CVE-2026-89028 vulnerability?
CVE-2026-89028 is a heap memory corruption vulnerability in the userspace SMB daemon of RouterOS, allowing a remote attacker to corrupt adjacent heap memory by providing a uniPwdLen value processed in the SMB1 SessionSetupAndX handler. The attacker sends a malformed SMB1 request with a uniPwdLen field that causes an integer underflow, resulting in the use of the resulting value as a copy length in a memory copy operation to a smaller heap buffer, corrupting adjacent heap memory.
Which RouterOS versions are vulnerable?
The vulnerable versions are all those up to 6.49.18 and up to 7.11.2. The fixed version is 7.24.0.
Is my router at risk?
A router is at risk if the SMB file sharing service is active and reachable from untrusted networks. Since the flaw concerns the SMB server, which is rarely used in production, most environments are not exposed if the service is disabled.
Is the CVE-2026-89028 vulnerability actively exploited?
As of the date of the article, it is not reported as exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as exploited.
How to protect the router from CVE-2026-89028?
Updating to RouterOS 7.24.0 is the primary solution. Alternatively, if the SMB service is not required, disabling it eliminates exposure to the attack vector.
Which RouterOS commands are needed to mitigate CVE-2026-89028?
Temporary mitigation: smb service
The flaw concerns the router’s SMB file sharing server, which almost no one uses in production: it should be turned off.
/ip smb print
/ip smb set enabled=no
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation restarts the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2026-89028?
CVE-2026-89028 has a CVSS v3.1 score of 7.5 (HIGH) and a CVSS v4.0 score of 8.2 (HIGH).
Which version fixes CVE-2026-89028?
CVE-2026-89028 is fixed in RouterOS version 7.24.0.
Is disabling the SMB service enough to mitigate CVE-2026-89028?
Yes, disabling the SMB service eliminates exposure to CVE-2026-89028 since the vulnerability resides in the SMB daemon.
Is CVE-2026-89028 in the CISA KEV catalog?
No, CVE-2026-89028 is not in the CISA KEV catalog.



