peter bassill · operator
$ cve CVE-2026-67277 JSON

CVE-2026-67277 KEV

8.2
HIGH · CVSS 3.1 · EPSS 1.6% (pctl 74)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-13.

Description

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Scoring

CVSS8.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS1.56% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2026-09-13
Public exploitnone known
Published2026-09-05
Last modified2026-09-11

CISA KEV

NameMikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Added2026-09-10
Due2026-09-13
Vendor / productMikroTik / RouterOS
Ransomware usenone reported

Affected (1)

VendorProduct
mikrotikrouteros

References

→ the Explorer  ·  watch your stack  ·  NVD