ZeroDayAlert

CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

MikroTik RouterOS Added to KEV 2026-09-10 Federal due 2026-09-13 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

MikroTik RouterOS contains a missing authentication control on a critical function within the btest service. This allows an attacker to trigger kernel memory disclosure and denial of service without valid credentials. The record does not specify which versions of RouterOS are affected, nor does it name a specific patch version.

How to check whether this touches you

  • Inventory all MikroTik RouterOS deployments in your estate, including version numbers from device configurations or management dashboards.
  • Establish whether the btest service is reachable from untrusted networks: check routing rules, firewall policy, and whether the device faces the internet or a DMZ without segmentation.
  • Query running RouterOS versions directly via SSH, web UI, or API; note that version strings alone do not confirm whether vendor mitigations have been applied, as backported security fixes are common.
  • If you run MikroTik management platforms or collectors, verify they do not expose RouterOS instances to unauthenticated access.

What to do

  1. Consult MikroTik's security advisories and release notes immediately to identify the specific patch version for your RouterOS release line.
  2. If you cannot patch within the federal due date (13 September 2026), isolate affected RouterOS devices from untrusted networks: restrict access to the btest service to authenticated administrative hosts only, using firewall rules or network segmentation.
  3. Review logs from the btest service for any unauthenticated connection attempts or anomalous memory-access patterns; enable verbose logging if available.
  4. If the device cannot be mitigated and remains internet-facing, escalate to your risk and compliance teams to determine whether continued operation complies with BOD 26-04 and your own security policy; discontinuation may be required.

If you find you were exposed

Exploitation of missing authentication vulnerabilities typically occurs before public disclosure. Examine btest service logs and system logs for the window between the device deployment and today, looking for unauthenticated access, memory dumps, or crashes. Kernel memory disclosures may not leave obvious forensic traces; if your log retention period has expired, retrospective detection will be limited to correlated alerts from intrusion detection or endpoint tools. Alert your incident response and forensics teams if you find evidence of unauthorised btest access.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-67277 is being exploited. It cannot tell you whether RouterOS is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →