CVE-2026-67277: MikroTik RouterOS Missing Authentication Flaw Added to CISA KEV
CISA added CVE-2026-67277, a missing authentication flaw in MikroTik RouterOS btest, to the KEV catalog on 2026-09-10 with a 2026-09-13 due date. Patch to 6.49.21, 7.23.4, or 7.24.2 today.
CVE-2026-67277: MikroTik RouterOS Missing Authentication Flaw Added to CISA KEV
TL;DR
CISA added CVE-2026-67277, a missing authentication for critical function vulnerability in MikroTik RouterOS's btest service, to the Known Exploited Vulnerabilities catalog on 2026-09-10 with a federal remediation due date of 2026-09-13. If you run RouterOS, inventory every instance today, confirm btest exposure, and upgrade to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable) per vendor guidance.
What is this vulnerability?
- CVE ID: CVE-2026-67277
- Vendor / product: MikroTik / RouterOS
- Vulnerability name: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Weakness: CWE-306 (Missing Authentication for Critical Function)
- CISA KEV status: Yes — added 2026-09-10, due 2026-09-13
- Known ransomware use: Unknown
- CVSS: 8.8 HIGH (CNA: cvd@cert.pl, CVSS 4.0) and 8.2 HIGH (NVD, CVSS 3.1)
- EPSS: 0.00869 (percentile 0.57059)
Per the official summary, RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With random-data=false, the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. The net effect is kernel memory disclosure and denial of service in the btest service.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
KEV vs CVSS vs EPSS
| Signal | What it measures | How to use it for this CVE |
|---|---|---|
| CISA KEV | Confirmed in-the-wild exploitation; carries a binding remediation due date for federal agencies | Treat as exploited. Prioritize CVE-2026-67277 above non-KEV work and drive to the 2026-09-13 due date. |
| CVSS | Theoretical severity of the flaw (8.8 HIGH per CNA, 8.2 HIGH per NVD) | Confirms network-reachable, no-privilege, no-interaction exploitation with high availability impact. Use for risk scoring and change-board justification. |
| EPSS | Modeled probability of exploitation in the next 30 days (0.00869, ~57th percentile) | Low near-term probability score does not override KEV. EPSS is a forecasting input, not a substitute for confirmed exploitation. |
Step-by-step remediation
- Inventory. Enumerate every MikroTik RouterOS instance across your estate — edge routers, branch CPE, lab gear, and cloud-hosted appliances. Record version, management plane exposure, and whether btest is reachable.
- Assess exposure. Determine which instances are internet-facing or reachable from untrusted segments. Per CISA guidance, stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
- Patch or mitigate. Upgrade to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable) in accordance with vendor instructions. If you cannot patch immediately, restrict access to the btest service and management interfaces to trusted networks only. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Apply BOD 26-04 and forensics triage requirements. Align remediation with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk and the associated Forensics Triage Requirements implementation guidance (links below).
- Verify. After upgrading, confirm the running firmware version on each device, re-test reachability of btest from untrusted networks, and validate that no anomalous kernel restarts or unexpected UDP test traffic persist.
- Close the ticket. Document the version applied, the exposure assessment, and the verification evidence. Retain records to demonstrate compliance with the 2026-09-13 due date.
FAQ
Is CVE-2026-67277 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-10, indicating confirmed exploitation in the wild.
What is the CISA due date for CVE-2026-67277? The federal remediation due date is 2026-09-13. Organizations outside the federal scope should treat this as a strong prioritization signal and patch on the same timeline where feasible.
Is this vulnerability internet-facing? The flaw is network-reachable (CVSS AV:N) and requires no privileges or user interaction. Any RouterOS instance with the btest service exposed to untrusted networks should be considered at risk. Evaluate each asset's internet exposure as part of your BOD 26-04 obligations.
Is there a known ransomware tie? CISA lists known ransomware use as Unknown for this CVE. Absence of a confirmed ransomware association does not reduce urgency given KEV status.
Which RouterOS versions fix CVE-2026-67277? The issue was fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). Upgrade to one of these or a later release per vendor instructions.
What is the CVSS score and EPSS score? CVSS is 8.8 HIGH (CNA, CVSS 4.0) and 8.2 HIGH (NVD, CVSS 3.1). EPSS is 0.00869, at the 0.57059 percentile. KEV status is the dominant signal here.