CVE-2026-67277
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Summary
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Affected software
Vendor: MikroTik · Product: RouterOS
Weakness types (CWE):
What to do
This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.
Related vulnerabilities in MikroTik
| CVE | Name | EPSS | Exploited |
|---|---|---|---|
| CVE-2018-14847 | MikroTik Router OS Directory Traversal Vulnerability | 96.1% | Yes |
| CVE-2018-7445 | MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability | 60.8% | Yes |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vu | 1.0% | Yes |
Is your domain exposed?
Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.
Get your free reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.