CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

Summary

MikroTik RouterOS has a critical vulnerability allowing kernel memory disclosure and denial of service in the btest service due to missing authentication. Users are advised to apply vendor-provided mitigations and comply with CISA's guidance on prioritizing security updates.

IFF Assessment

FOE

This vulnerability allows for kernel memory disclosure and denial of service, which are significant threats to system integrity and availability.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for kernel memory disclosure and denial of service, indicating a high impact on confidentiality and availability. The 'missing authentication for critical function' often implies a low attack complexity.

CISA KEV: Listed as actively exploited. Federal patch due: September 13, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in MikroTik RouterOS poses a significant risk due to the potential for memory disclosure and denial of service attacks. Defenders should prioritize applying vendor-provided patches and mitigations, especially for internet-facing devices, and adhere to CISA's directives for risk-based patching.

Read Full Story →