CVE-2026-67277 is an unauthenticated pre-authentication flaw in MikroTik RouterOS's btest (bandwidth test) service (CWE-306, Missing Authentication) that allows a remote attacker to disclose kernel memory and trigger a denial-of-service kernel restart. It is remotely exploitable over the network without authentication or user interaction and is actively exploited in the wild (CISA KEV listed).
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-05
Added to CISA KEV: 2026-09-10 5 DAYS BETWEEN CVE AND KEV
CVE-2026-67277 is a critical vulnerability in MikroTik RouterOS that stems from a missing authentication check for "btest" (bandwidth test) connections, allowing unauthenticated clients to interact with the service before a primary session is established. This flaw is significant because it enables an attacker to perform kernel memory disclosure and trigger a denial-of-service (DoS) condition, posing a substantial risk to network infrastructure. Because this vulnerability is actively exploited in the wild, it has been formally included in CISA's Known Exploited Vulnerabilities (KEV) Catalog.
RouterOS permits a "btest" connection from an unauthenticated client before the primary session is authenticated, allowing the attacker to initiate an IPv4 UDP test with "random-data=false". This causes the service to transmit an uninitialised tail from a kernel packet buffer, exposing kernel memoryβ¦
CVE-2026-67277 Detail Description RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kβ¦
Kernel memory disclosure and denial of service in MikroTik RouterOS. An unauthenticated client can use this state to start an IPv4 UDP test. transmits an ...
Kernel memory disclosure and denial of service in MikroTik RouterOS. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) ...
MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.