Junglewise Threat Intelligence

CVE-2026-67277: MikroTik RouterOS missing authentication in btest service

CVE-2026-67277 · Severity: critical · Exploited in the wild · Published 2026-09-10

Executive brief

MikroTik RouterOS is widely used in network routers and gateways to manage enterprise and ISP networks. A missing authentication flaw in the btest service allows attackers without credentials to leak sensitive kernel memory and crash the device, disrupting network operations and potentially exposing internal system details. The vulnerability is actively being exploited by attackers.

Technical details

MikroTik RouterOS contains a missing authentication vulnerability in the btest service, a critical component responsible for network diagnostics and testing functionality. The vulnerability allows unauthenticated remote attackers to invoke privileged functions without providing valid credentials. An attacker with network access can exploit this to read sensitive kernel memory, potentially disclosing cryptographic keys, configuration data, or other sensitive information, and trigger a denial of service by causing the service or device to crash. The vulnerability is network-reachable and requires no authentication or user interaction; exploitation is straightforward and is actively occurring in the wild.

Affected products

  • MikroTik RouterOS

Timeline

  • 2026-09-10: disclosed
  • exploited: Being actively exploited in the wild

Related threats