Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-13 ยท updated: 2026-09-13 ยท tags: [cve, mikrotik, routeros, unauthenticated, information-disclosure, edge-device, kev] ยท confidence: high ยท severity: high ยท affected_sectors: [global] ยท au_impact: false

CVE-2026-67277 is a missing-authentication flaw in MikroTik RouterOS, rated CVSS 3.1 8.2 (HIGH). RouterOS accepts a "related" bandwidth-test (btest) connection before the corresponding primary session has completed authentication; an unauthenticated client can use that state to start an IPv4 UDP test, and with random-data=false the sender transmits an uninitialised tail from a kernel packet buffer. CISA added it to the Known Exploited Vulnerabilities catalogue on 10 September 2026 on evidence of active exploitation, describing it as a missing authentication for a critical function.

Attribute Detail
CVE CVE-2026-67277
CVSS 8.2 (CVSS 3.1, AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
Vendor / product MikroTik โ€” RouterOS
NVD published 2026-09-05
KEV added 2026-09-10
Reported 2026-09-13