MikroTik RouterOS Vulnerability: Critical Function Missing Authentication
- Severity
- HIGH
- Affected component
- mikrotik routeros (other)
- Patched version
- Not yet available
An early warning has been issued for a high severity vulnerability in MikroTik RouterOS. The vulnerability, tracked as CVE-2026-67277, reportedly allows kernel memory disclosure and denial of service in the btest service due to missing authentication for a critical function.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-67277 to its Known Exploited Vulnerabilities (KEV) catalog. This indicates that the vulnerability is under active exploitation in the wild. The vulnerability is a missing authentication for a critical function in MikroTik RouterOS, which could lead to kernel memory disclosure and denial of service in the btest service.
Professional software engineers using MikroTik RouterOS should assess their exposure by reviewing their configurations for the btest service and ensuring that they are running the latest version of the software. No authoritative version range has been published yet, so it is recommended to upgrade to the latest available version.
What to do about it
- Upgrade MikroTik RouterOS to the latest version immediately.
- Review and harden configurations for the btest service to minimize exposure.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
- Implement additional monitoring and logging for any unusual activity related to the btest service.
- Consider disabling the btest service if it is not required for your use case until a patch is available.
How 0Day would have caught this
mikrotik routeros is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using MikroTik RouterOS, you may be affected. No authoritative version range has been published yet, so it is recommended to upgrade to the latest version and review your configurations.
What should I do right now?
Upgrade MikroTik RouterOS to the latest version and review your configurations for the btest service. Monitor the primary sources for updates on the vulnerability and any official fixes.
Has this been exploited in the wild?
Yes, the vulnerability is reportedly being exploited in the wild.