CISA added CVE-2026-67277 to the Known Exploited Vulnerabilities catalog on 2026-09-10, confirming active exploitation of a missing-authentication flaw in MikroTik RouterOS that leaks kernel memory and can restart the device.
What Is It
RouterOS accepts a "related" btest connection before the corresponding primary session has finished authenticating. An unauthenticated client can abuse that state to start an IPv4 UDP test. With random-data=false, the sender transmits an uninitialized tail from a kernel packet buffer; a direct kernel memory disclosure. Separately, an unchecked, inverted packet-size interval triggers an unsigned integer underflow, producing anomalously large fragmented output and able to restart the RouterOS kernel.
CISA tracks it as "MikroTik RouterOS Missing Authentication for Critical Function Vulnerability," mapped to CWE-306. CERT.PL assigned a CVSS 4.0 base score of 8.8 (HIGH), vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N.
Why It Matters
No credentials, no user interaction, network-reachable. CISA's SSVC assessment rates exploitation as active and automatable: yes, with partial technical impact; a profile that generally lends itself to opportunistic, internet-wide scanning rather than hand-delivered, targeted use, though neither CISA nor CERT.PL has published details on how the observed exploitation is actually being conducted. The pairing of an info leak with a remote kernel restart gives attackers both reconnaissance material and a denial-of-service primitive against edge routing infrastructure. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
MikroTik RouterOS, per the CERT.PL-supplied affected ranges:
- 6.0.0 up to (but not including) 6.49.21
- 7.0.0 up to (but not including) 7.23.4
- 7.24 up to (but not including) 7.24.2
Patch Status
Fixed in 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
CISA's required action: apply mitigations per vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. The KEV due date is 2026-09-13: three days after listing. Forensic triage requirement: No.
Sources
- CISA KEV Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277
- NVD, CVE-2026-67277, https://nvd.nist.gov/vuln/detail/CVE-2026-67277
- MikroTik Security Advisory (September 2026), https://mikrotik.com/supportsec/september-2026-vulnerability/
- CERT.PL, MikroTik RouterOS CVE, https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- CERT.PL, Vulnerabilities in MikroTik RouterOS Actively Exploited, https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- MikroTik Forum, 6.49.21 Long-term released, https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- MikroTik Forum, 7.23.4 Long-term released, https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- MikroTik Forum, 7.24.2 Stable released, https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- Reversing MikroTik's Silent Patch; https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk