Catalog analysis: CISA added this entry on September 10, 2026. The entry reflects catalog information retrieved on September 10, 2026, not a snapshot archived on the inclusion date. This site’s publication date is shown separately. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-67277 is a vulnerability in MikroTik RouterOS characterized by missing authentication for a critical function (CWE-306). The flaw resides specifically within the btest service. If exploited, this vulnerability could allow an attacker to trigger kernel memory disclosure or cause a denial of service (DoS) condition on the affected device.
Exposure and applicability
This vulnerability applies to MikroTik RouterOS deployments where the btest service is active and reachable. Because the flaw involves missing authentication, any entity capable of interacting with the btest service may be able to trigger the disclosed impacts. Infrastructure owners should identify all RouterOS assets and determine if the btest service is enabled and exposed to untrusted networks.
Remediation priorities
Our analysis suggests prioritizing remediation based on the asset’s network positioning and the operational criticality of the device. We recommend the following priority sequence:
- Immediate Mitigation: Apply vendor-supplied mitigations as detailed in MikroTik’s security instructions. This is the primary method for reducing exposure.
- Exposure Reduction: For devices where immediate patching is not feasible, defenders should evaluate whether the
btestservice is required for business operations and disable it or restrict access via firewall rules to trusted management IPs only. - Asset Inventory: Identify all RouterOS instances across the environment to ensure no legacy or shadow infrastructure remains unpatched.
How to validate remediation
To verify that exposure has been reduced, vulnerability management teams should move beyond simple version checks. Validation should include:
- Service State Verification: Confirming through configuration audits that the
btestservice is either disabled or restricted to authorized sources. - Vendor-Specified Validation: Following the specific verification steps provided in the vendor’s mitigation guidance to ensure the fix is active and functioning as intended.
Verification is only complete when it is confirmed that the attack vector (the unauthenticated access to btest) is closed.
Limits and open questions
While the impact of kernel memory disclosure and DoS is clear, the source does not provide information on whether this vulnerability has been leveraged in active ransomware campaigns. Additionally, the specific versions of RouterOS affected are not listed in the summary; users must refer to the vendor’s security advisory for exact version ranges. Residual risk remains if the btest service is required for operational testing but cannot be fully secured via authentication, as this may leave a window of exposure during active use.
Source and editorial note
CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability · Source date: September 10, 2026 · Retrieved September 10, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗