CVE-2026-67277

CVE-2026-67277 is a high-severity vulnerability in Mikrotik Routeros with a CVSS 3.x base score of 8.2. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-09-10). The underlying weakness is classified as CWE-306.

Key facts

Description

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Frequently asked questions

What is CVE-2026-67277?
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
How severe is CVE-2026-67277?
CVE-2026-67277 has a CVSS 3.x base score of 8.2, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability high.
Is CVE-2026-67277 being actively exploited?
Yes. CVE-2026-67277 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-09-10, which means active exploitation has been confirmed. It should be prioritised for remediation.
What products are affected by CVE-2026-67277?
CVE-2026-67277 affects Mikrotik Routeros. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-67277?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
When was CVE-2026-67277 published?
CVE-2026-67277 was published on 2026-09-05 and last updated on 2026-09-11.

References

Affected products (1)

More vulnerabilities in Mikrotik Routeros

All CVEs affecting Mikrotik Routeros →

Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities

Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →

Threat intelligence

Threat-intel indicators referencing this CVE: