First published · Last updated
CVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
A missing-authentication flaw in MikroTik RouterOS's btest service can lead to kernel memory disclosure and denial of service. The advisory directs applying vendor mitigations and following CISA BOD 26-04 and forensics guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 7/10
- Geographic reach
- 4/10
- Global importance
- 5/10
- Impact magnitude
- 5/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Stakeholders are told to apply mitigations or discontinue use and to follow CISA patching requirements, indicating required security action.

