MikroTik RouterOS Missing Authentication for Critical Function Vulnerability (btest service)
First seen Sep 11, 2026 · Updated Sep 11, 2026
CVE-2026-67277 is a missing authentication vulnerability in MikroTik RouterOS's btest (bandwidth test) service, allowing unauthenticated attackers to trigger kernel memory disclosure and denial of service. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild, with a short remediation window (added 2026-09-10, due 2026-09-13).
Technical Analysis
The vulnerability resides in RouterOS's btest service, which lacks proper authentication checks for a critical function, enabling unauthenticated network-based attackers to send crafted requests that leak kernel memory contents or crash the device via denial of service. This class of flaw is particularly dangerous on edge/perimeter devices like MikroTik routers, which are widely deployed as gateways, VPN endpoints, and traffic shapers in enterprise and ISP networks. Successful exploitation could expose sensitive kernel data (potentially including session tokens or configuration secrets) or disrupt network availability, and compromised routers are frequently repurposed for botnet activity or as pivot points for further lateral movement. Organizations running AI agent infrastructure behind or through affected MikroTik routers face risk if the devices are used as network gateways, VPN concentrators, or traffic managers for agent-to-tool or agent-to-API communications, since a DoS or memory leak on this hardware could disrupt agent connectivity or expose credentials/API keys transiting the network.
Affected Systems
MikroTik RouterOS devices with the btest (bandwidth test) service enabled and exposed to network access; specific affected version ranges not disclosed in source data, administrators should consult MikroTik's official advisory for exact version details.
Indicators of Compromise
- No specific file hashes, IPs, or domains provided in source data; monitor for anomalous btest service traffic and unexpected router reboots/crashes as behavioral indicators.
Remediation Steps
- 1
Apply vendor patch
Update RouterOS to the latest version containing the fix for CVE-2026-67277 as soon as MikroTik releases it.
- 2
Disable or restrict btest service
Disable the btest (Bandwidth Test) service if not required, or restrict access to trusted management networks/IP ranges via firewall rules.
- 3
Segment management interfaces
Ensure router management and diagnostic services are not exposed to the public internet; place them behind VPN or dedicated management VLANs.
- 4
Monitor for exploitation
Review router logs and network traffic for signs of btest service abuse, unexpected crashes, or memory disclosure attempts.
- 5
Audit agent network dependencies
Identify any AI agent or automation pipelines relying on network paths through affected MikroTik devices and validate continuity/security controls.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.