• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-67277: pre-auth denial of service in MikroTik RouterOS

An unauthenticated network attacker can trigger a vulnerability in MikroTik RouterOS's btest service to crash the kernel and cause disclosure of kernel memory, tracked as CVE-2026-67277. Versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2 are affected. No user interaction or account is required; an attacker only needs network access to the RouterOS btest service to exploit the flaw.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
8.2HIGH
EPSS
0.0156
CWE
CWE-306
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-09-13, so prioritize applying vendor fixes or mitigations immediately.

What is CVE-2026-67277?

An unauthenticated network attacker can trigger a vulnerability in MikroTik RouterOS's btest service to crash the kernel and cause disclosure of kernel memory, tracked as CVE-2026-67277. Versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2 are affected. No user interaction or account is required; an attacker only needs network access to the RouterOS btest service to exploit the flaw. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Which versions of MikroTik RouterOS are affected?

BRANCHAFFECTEDFIXED
7.x7.24 – before 7.24.27.24.2
7.x7.0.0 – before 7.23.47.23.4
6.x6.0.0 – before 6.49.216.49.21

Is CVE-2026-67277 being exploited?

CISA added CVE-2026-67277 to the Known Exploited Vulnerabilities catalog on 2026-09-10, and US federal agencies must remediate by 2026-09-13.

How to fix CVE-2026-67277

  1. Upgrade RouterOS to 6.49.21, 7.23.4, or 7.24.2 as appropriate for your device.
  2. If immediate upgrade is not possible, restrict network access to the btest service and block unsolicited UDP traffic to the device.
  3. Follow MikroTik guidance and monitor device logs and network traffic for anomalous btest connections.
  4. Apply CISA and vendor mitigation guidance and prioritize patches per BOD 26-04 requirements.

Frequently asked questions

Is CVE-2026-67277 being actively exploited?

CISA added CVE-2026-67277 to its Known Exploited Vulnerabilities catalog on 2026-09-10, requiring remediation by 2026-09-13 for covered agencies.

Which RouterOS versions are affected by CVE-2026-67277?

MikroTik RouterOS versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2 are affected.

Is there a patch for CVE-2026-67277?

Yes, MikroTik published fixes in RouterOS 6.49.21, 7.23.4, and 7.24.2.

Does CVE-2026-67277 require authentication?

No, the vulnerability in RouterOS's btest service can be triggered by an unauthenticated network client.

References