CVE-2026-39042
the affected product
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial of service via the unflatten() function in libumsg.so.
- CVSS
- 7.5
- EPSS
- 0.41% 33.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14