Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-67277 2026-09-10

MikroTik RouterOS btest Flaw (CVE-2026-67277) Added to CISA KEV Amid Active Exploitation

"CISA added CVE-2026-67277 to the Known Exploited Vulnerabilities catalog on 2026-09-10, confirming active exploitation of a missing-authentication flaw in MikroTik RouterOS that leaks kernel memory and can restart the…"

CISA added CVE-2026-67277 to the Known Exploited Vulnerabilities catalog on 2026-09-10, confirming active exploitation of a missing-authentication flaw in MikroTik RouterOS that leaks kernel memory and can restart the device.

What Is It

RouterOS accepts a "related" btest connection before the corresponding primary session has finished authenticating. An unauthenticated client can abuse that state to start an IPv4 UDP test. With random-data=false, the sender transmits an uninitialized tail from a kernel packet buffer; a direct kernel memory disclosure. Separately, an unchecked, inverted packet-size interval triggers an unsigned integer underflow, producing anomalously large fragmented output and able to restart the RouterOS kernel.

CISA tracks it as "MikroTik RouterOS Missing Authentication for Critical Function Vulnerability," mapped to CWE-306. CERT.PL assigned a CVSS 4.0 base score of 8.8 (HIGH), vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N.

Why It Matters

No credentials, no user interaction, network-reachable. CISA's SSVC assessment rates exploitation as active and automatable: yes, with partial technical impact; a profile that generally lends itself to opportunistic, internet-wide scanning rather than hand-delivered, targeted use, though neither CISA nor CERT.PL has published details on how the observed exploitation is actually being conducted. The pairing of an info leak with a remote kernel restart gives attackers both reconnaissance material and a denial-of-service primitive against edge routing infrastructure. Known ransomware campaign use is listed as Unknown.

What's Vulnerable

MikroTik RouterOS, per the CERT.PL-supplied affected ranges:

Patch Status

Fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

CISA's required action: apply mitigations per vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. The KEV due date is 2026-09-13: three days after listing. Forensic triage requirement: No.

Sources