Buffer Overflow Vulnerability in MikroTik RouterOS
CVE-2026-67277

8.8HIGH

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
5 September 2026

Badges

📈 Score: 657👾 Exploit Exists🦅 CISA Reported

What is CVE-2026-67277?

CVE-2026-67277 is a critical buffer overflow vulnerability found in MikroTik RouterOS, which is a widely used operating system for routing devices. MikroTik RouterOS allows users to manage networking tasks and provides various functionalities essential for maintaining network performance and security. This vulnerability arises when the RouterOS processes "related" btest connections before first completing the required authentication for the primary session. An unauthenticated client can exploit this state to initiate an IPv4 UDP test, which may transmit uninitialized data from a kernel packet buffer, leading to instability within the RouterOS environment. Specifically, this results in an unsigned integer underflow during packet processing, which can generate unusually large fragmented outputs and potentially allow the attacker to restart the RouterOS kernel. Such instability poses a significant risk to organizations utilizing MikroTik devices, affecting their network reliability and security posture.

Potential impact of CVE-2026-67277

  1. System Downtime: The exploitation of this vulnerability could enable attackers to cause the RouterOS kernel to restart, resulting in unpredictable behavior and potential downtime for critical network services. This can disrupt business operations and lead to loss of productivity.

  2. Unauthorized Access and Control: Given that the vulnerability allows unauthenticated clients to initiate processes, it could facilitate unauthorized access to the network infrastructure. Attackers could leverage this access to manipulate network settings, leading to further exploitation or the establishment of persistent access points within the network.

  3. Increased Attack Surface for Subsequent Exploits: By causing instability and allowing unauthorized interactions, this vulnerability could increase the attack surface for further malicious activities. For example, it could be used as a stepping stone for launching more sophisticated attacks, including data exfiltration or lateral movement within the network, thus heightening overall security risks for affected organizations.

CISA has reported CVE-2026-67277

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-67277 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

RouterOS 7.24 < 7.24.2

RouterOS 7.0.0 < 7.23.4

RouterOS 6.0.0 < 6.49.21

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🦅

    CISA Reported

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sławomir Rozbicki (CERT.PL)
.