CriticalCISA KEVSep 10, 2026

CVE-2026-67277: MikroTik RouterOS added to CISA KEV

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

Why it matters

This item has practical defensive relevance and is worth validating against your asset inventory, telemetry and patch state.

What defenders should do

Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.

Verify at the source

CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →

Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security tools