Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-67277

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS btest service missing authentication allows kernel memory disclosure. CVSS 8.2 (high), CISA KEV deadline September 13, 2026.

cat cve-2026-67277.json
Vendor
MikroTik
Product
RouterOS
CVSS
8.2
EPSS (exploit probability)
1.6%
Status
kev
CISA patch-by (BOD 22-01)
Published

An unauthenticated client can reach the RouterOS btest (bandwidth test) service without authenticating. The missing authentication check allows the attacker to trigger kernel memory disclosure from the service. Under certain packet-size conditions, the same flaw causes unsigned integer underflow and anomalously large fragmented output, which can restart the RouterOS kernel.

CISA added CVE-2026-67277 to its Known Exploited Vulnerabilities catalog on September 10, 2026. Federal agencies must remediate by September 13, 2026. Per the NVD entry, fixes are in RouterOS 6.49.21, 7.23.4 (Long-term), and 7.24.2 (Stable). Update to your channel’s current fixed version.