Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Eeee

#20934of 57,586
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-93715
6.5
2026-09-16
Mikrotik · Routeros · CVE-2026-56719
**Name of the Vulnerable Software and Affected Versions** MikroTik RouterOS versions prior to 7.24 **Description** An out-of-bounds read exists in the userspace SMB daemon. Unauthenticated attackers can read beyond the end of the request buffer by providing a crafted `uniPwdLen` field value within a minimal SMB1 SessionSetupAndX frame. This issue occurs in the SessionSetupAndX handler before credential validation, which may expose sensitive memory contents. **Recommendations** Update MikroTik RouterOS to version 7.24 or later.
PT-2026-93728
7.5
2026-09-16
Mikrotik · Routeros · CVE-2026-89028
**Name of the Vulnerable Software and Affected Versions** MikroTik RouterOS versions prior to 7.24 **Description** A heap memory corruption issue exists in the userspace SMB daemon. A remote attacker can corrupt adjacent heap memory by sending a malformed SMB1 request to the SMB1 SessionSetupAndX handler. By supplying a crafted `uniPwdLen` value, an integer underflow is triggered, which causes the resulting value to be used as the copy length during a memory copy operation into a smaller heap buffer. **Recommendations** Update MikroTik RouterOS to version 7.24 or later.