Mikrotik · Routeros · CVE-2026-89028
**Name of the Vulnerable Software and Affected Versions**
MikroTik RouterOS versions prior to 7.24
**Description**
A heap memory corruption issue exists in the userspace SMB daemon. A remote attacker can corrupt adjacent heap memory by sending a malformed SMB1 request to the SMB1 SessionSetupAndX handler. By supplying a crafted `uniPwdLen` value, an integer underflow is triggered, which causes the resulting value to be used as the copy length during a memory copy operation into a smaller heap buffer.
**Recommendations**
Update MikroTik RouterOS to version 7.24 or later.