MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
MikroTik RouterOS contains a missing authentication flaw in its bandwidth-test (btest) service that allows any unauthenticated network attacker to trigger kernel memory disclosure or crash the device. The service accepts a secondary "related" connection before the primary session has authenticated, granting access to a privileged state without credentials. Affected versions span the v6 branch below 6.49.21 and the v7 branch below 7.23.4 (long-term) or 7.24.2 (stable). The vulnerability is actively exploited in the wild as part of the broader MikroTrick attack campaign.
The btest service in RouterOS fails to enforce authentication before accepting a "related" secondary connection, a violation of CWE-306 (Missing Authentication for Critical Function). This trust-boundary failure lets an unauthenticated client reach a session state that should only be available after login. Once in that state, two compounding flaws activate: running a UDP test with random-data=false causes the service to transmit uninitialized kernel packet buffer contents, and a separate unchecked inverted packet-size interval triggers an unsigned integer underflow producing anomalously large fragmented output.
An attacker with network access to the btest service sends a crafted "related" connection request, bypassing the authentication gate entirely. Setting random-data=false in the test parameters causes the router to return uninitialized kernel memory to the attacker, disclosing potentially sensitive data from the kernel buffer. Supplying a malformed inverted packet-size interval triggers the integer underflow, which can force a kernel restart and take the device offline. No credentials are required at any stage, and CERT Polska has confirmed active exploitation of RouterOS devices reachable from the internet.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If MikroTik RouterOS runs inside your authorization boundary, CVE-2026-67277 is a direct concern. This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its September 13, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is an assessor finding. An overdue one is visible to both your assessor and your sponsoring agency. Your path forward is either remediation now or formal documentation of the mitigation and the delay.
Knox does not patch MikroTik RouterOS on your behalf. Under the FedRAMP shared-responsibility model, remediating that vulnerability is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, along with Knox's automated continuous monitoring platform and audit-artifact coverage to support your next assessment. Applying the fix is your work. Managing your compliance posture while you do it is not something you have to handle on your own.
Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance gaps, including cases like CVE-2026-67277. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the earliest possible window to act.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
An unremediated CVE-2026-67277 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding now and documenting the circumstances of the delay is what keeps your authorization standing and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)








