CVE-2026-67277
published 2026-09-05CVE-2026-67277: RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this…
PriorityP182high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-13
Exploited in the wild
EPSS
1.56%
74.4th percentile
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mikrotik | routeros | >= 6.0 < 6.49.21 | 6.49.21 |
| mikrotik | routeros | >= 6.0.0 < 6.49.21 | 6.49.21 |
| mikrotik | routeros | >= 7.0 < 7.23.4 | 7.23.4 |
| mikrotik | routeros | >= 7.0.0 < 7.23.4 | 7.23.4 |
| mikrotik | routeros | >= 7.24 < 7.24.2 | 7.24.2 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication.
ghsa_unreviewed·2026-09-05
CVE-2026-67277 [HIGH] CWE-306 RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication.
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
VulDB
Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 integer underflow (EUVD-2026-72025)
vuldb·2026-09-05·CVSS 8.8
CVE-2026-67277 [HIGH] Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 integer underflow (EUVD-2026-72025)
A vulnerability described as very critical has been identified in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. The impacted element is an unknown function. Such manipulation leads to integer underflow.
This vulnerability is uniquely identified as CVE-2026-67277. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
VulnCheck
MikroTik RouterOS Missing Authentication for Critical Function
vulncheck·2026·CVSS 8.8
CVE-2026-67277 [HIGH] MikroTik RouterOS Missing Authentication for Critical Function
MikroTik RouterOS Missing Authentication for Critical Function
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected: MikroTik RouterOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Explo
CISA
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
cisa·2026-09-10·CVSS 8.8
CVE-2026-67277 [HIGH] CWE-306 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Vulnerability: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Affected: MikroTik RouterOS
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
No
No detection rules found.
No public exploits indexed.
Hackernews
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
blogs_hackernews·2026-09-12·CVSS 8.8
CVE-2026-42016 [HIGH] CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect , and MikroTik RouterOS to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation in the wild.
Details of the vulnerabilities are as follows -
CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's s
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cvehttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800https://mikrotik.com/supportsec/september-2026-vulnerability/https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277
2026-09-05
Published
2026-09-10
Added to CISA KEV
Exploited in the wild