PatchSiren cyber security CVE debrief
CVE-2026-7668 MikroTik CVE debrief
A medium-severity out-of-bounds read vulnerability exists in MikroTik RouterOS 6.49.8 within the SCEP Endpoint component. The flaw resides in the ASN1_STRING_data function in nova/lib/www/scep.p, where manipulation of the transactionID or messageType arguments can trigger memory access beyond allocated bounds. The attack vector is network-accessible and requires no authentication, though the CVSS 4.0 vector indicates low impacts to confidentiality, integrity, and availability. The vulnerability was published on 2026-05-02 and last modified on 2026-05-20. Public exploit availability is noted in source metadata. The vendor has confirmed remediation in current v6.x and v7.x releases.
- Vendor
- MikroTik
- Product
- RouterOS
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-02
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-02
- Advisory updated
- 2026-05-20
Who should care
Network administrators managing MikroTik RouterOS deployments with SCEP functionality enabled; security teams tracking publicly exploitable infrastructure vulnerabilities; organizations with remote-accessible certificate enrollment endpoints.
Technical summary
The vulnerability is an out-of-bounds read (CWE-125/CWE-119) in the ASN1_STRING_data function handling SCEP protocol data. Affected versions: RouterOS 6.49.8. Attack complexity is low, no privileges required, no user interaction needed. Public exploits exist. Vendor fix available in current release branches.
Defensive priority
medium
Recommended defensive actions
- Upgrade MikroTik RouterOS to the latest v6.x or v7.x version as recommended by the vendor
- Review SCEP endpoint exposure and restrict network access where unnecessary
- Monitor for anomalous SCEP traffic patterns targeting transactionID or messageType fields
- Validate firmware integrity after upgrade via vendor-signed packages
Evidence notes
Vulnerability disclosed via VulDB with NVD entry. Vendor acknowledgment present in description. Exploit existence flagged in CVSS 4.0 vector (E:P). CPE criteria not populated in source; vendor identification marked low-confidence requiring review.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7668 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7668
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7668 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7668
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ezio315/cve/issues/4
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/798623
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/360804
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/360804/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.