## Overview
CISA added CVE-2026-67277 to its Known Exploited Vulnerabilities (KEV) catalog on September 10, 2026. This addition signals a federal deadline for agencies to patch affected systems. Evidence of exploitation has surfaced, prompting urgency in addressing the vulnerability.
## Technical Details
MikroTik RouterOS suffers from a missing authentication vulnerability in the btest service. The issue arises when RouterOS accepts a "related" btest connection before the primary session completes authentication. An unauthenticated client can exploit this state to initiate an IPv4 UDP test. When the sender sets "random-data=false," it transmits an uninitialized tail from a kernel packet buffer. This leads to an unchecked, inverted packet-size interval, causing unsigned integer underflow. The result is anomalously large fragmented output, which can restart the RouterOS kernel.
## Impact
The vulnerability allows for kernel memory disclosure and potential denial of service. An attacker could exploit this flaw to disrupt network services or gain unauthorized access to sensitive information. Given the CVSS score of 8.8, this vulnerability poses a significant risk to affected systems.
## Mitigation
MikroTik has released patches in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). Users must upgrade their RouterOS installations to these versions immediately to mitigate the risk. Regularly check for updates and apply security patches as they become available.
CSURFACE Threat Sensor