DIRAS TAKE
Urgent — CISA added this issue to its Known Exploited Vulnerabilities catalog with a remediation deadline of 2026-09-13, so prioritize applying vendor fixes or mitigations immediately.
What is CVE-2026-67277?
An unauthenticated network attacker can trigger a vulnerability in MikroTik RouterOS's btest service to crash the kernel and cause disclosure of kernel memory, tracked as CVE-2026-67277. Versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2 are affected. No user interaction or account is required; an attacker only needs network access to the RouterOS btest service to exploit the flaw. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Which versions of MikroTik RouterOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.24 – before 7.24.2 | 7.24.2 |
| 7.x | 7.0.0 – before 7.23.4 | 7.23.4 |
| 6.x | 6.0.0 – before 6.49.21 | 6.49.21 |
Is CVE-2026-67277 being exploited?
CISA added CVE-2026-67277 to the Known Exploited Vulnerabilities catalog on 2026-09-10, and US federal agencies must remediate by 2026-09-13.
How to fix CVE-2026-67277
- Upgrade RouterOS to 6.49.21, 7.23.4, or 7.24.2 as appropriate for your device.
- If immediate upgrade is not possible, restrict network access to the btest service and block unsolicited UDP traffic to the device.
- Follow MikroTik guidance and monitor device logs and network traffic for anomalous btest connections.
- Apply CISA and vendor mitigation guidance and prioritize patches per BOD 26-04 requirements.
Frequently asked questions
Is CVE-2026-67277 being actively exploited?
CISA added CVE-2026-67277 to its Known Exploited Vulnerabilities catalog on 2026-09-10, requiring remediation by 2026-09-13 for covered agencies.
Which RouterOS versions are affected by CVE-2026-67277?
MikroTik RouterOS versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2 are affected.
Is there a patch for CVE-2026-67277?
Yes, MikroTik published fixes in RouterOS 6.49.21, 7.23.4, and 7.24.2.
Does CVE-2026-67277 require authentication?
No, the vulnerability in RouterOS's btest service can be triggered by an unauthenticated network client.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67277
- cve.org/CVERecord?id=CVE-2026-67277
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277
- cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited
- npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain
- mikrotik.com/supportsec/september-2026-vulnerability
- forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- All MikroTik CVEs on CVE Radar
- CVEs published in September 2026