🔥 New: Continuous AI Pentesting. Always-on, across all exposed assets. Learn More 🔥 New: Continuous AI Pentesting!
Back to Blog

Emerging Threat: (CVE-2026-67281) MikroTik RouterOS Unauthenticated File Read via WebFig

Sample of assets impacted by MikroTik file read vulnerability, identified by the CyCognito Platform

What is CVE-2026-67281?

CVE-2026-67281 is an unauthenticated file read vulnerability in WebFig, the web-based management interface in MikroTik RouterOS. A newly allocated session on the /jsproxy path retains a stale, uninitialized principal pointer that WebFig then uses for file authorization decisions.

The vulnerability carries a CVSS v4.0 base score of 8.7 (High). A CVSS v3.1 base score has not been assigned in the CVE record at the time of writing. The record maps the flaw to both CWE-824, access of uninitialized pointer, and CWE-22, improper limitation of a pathname to a restricted directory.

Exploitation is pre-authentication. An attacker with network access to the WebFig interface manipulates the allocator so that the file-serving routine dereferences an uninitialized pointer with elevated privileges, then supplies parent-directory traversal sequences inside an encrypted URI to escape the WebFig namespace. The result is read access to root-owned files on the device, including the configuration stores that hold credentials. On a router, that outcome matters beyond the device itself, because recovered credentials frequently unlock adjacent management interfaces, VPN endpoints, and monitoring systems.

CVE-2026-67281 was disclosed as part of a cluster of RouterOS vulnerabilities fixed in the same release. The in-the-wild exploitation CERT Polska has reported for that release involves the MikroTrick chain against the SSH service, not WebFig. There is no public reporting of CVE-2026-67281 being exploited in attacks at the time of writing, and defenders should treat the absence of confirmed exploitation as a timing observation rather than a reason to deprioritize.

What assets are affected by CVE-2026-67281?

The affected component is WebFig in RouterOS. Vulnerable version ranges span all three maintained branches: RouterOS 6.0.0 up to but not including 6.49.21, RouterOS 7.0.0 up to but not including 7.23.4, and RouterOS 7.24 up to but not including 7.24.2. Because the fixed builds are the newest release in each branch, essentially every RouterOS device that has not been updated since the release falls inside the affected range.

In practice, an affected asset is a MikroTik router, switch, wireless access point, or Cloud Hosted Router instance with the www or www-ssl service reachable from an untrusted network. These devices concentrate at the network edge: branch and retail-site routers, small-office customer premises equipment, site-to-site VPN terminators, and low-cost aggregation gear in distributed estates. Cloud Hosted Router deployments add a second population that sits directly on public address space by design.

Two deployment habits push this population toward internet exposure. RouterOS management services are commonly left bound to all interfaces rather than restricted to a management address range, so WebFig answers on the WAN side unless an administrator has deliberately constrained it. And the devices themselves are often installed by integrators, acquired with a site, or inherited from a partner-run network, which means the organization carrying the risk is frequently not the organization that configured the box. The RouterOS 6.x long-term branch compounds this, because it remains in production on hardware old enough that nobody is checking release notes.

What does our data show about exposure patterns?

Exposure in this set is led by Consumer Discretionary at 46.8% of observed assets, with Industrials contributing 19.1%. Consumer Staples accounts for 7.0%, and the remaining sectors together make up 27.1%.

The concentration in Consumer Discretionary tracks how retail, apparel, and hospitality organizations build their networks. These are estates measured in sites rather than data centers, where each store, franchise location, or regional office needs a connection at a per-site cost that favors inexpensive edge hardware.

Provisioning is often handled by a local integrator or a franchisee working from a template, and the resulting devices are rarely enrolled in the corporate configuration management that governs headquarters infrastructure.

Industrials shows a related pattern for a different reason: distributed plant, depot, and logistics sites accumulate network equipment across decades of expansion and acquisition, and decommissioning lags the operational change that made a link redundant.

Read across sectors, the pattern points less at RouterOS itself than at ownership of the management plane. Exposure here is produced by devices whose administrative interface was never scoped to a management network, sitting in parts of the estate where nobody holds a current inventory. Two caveats belong on this reading.

A significant share of these assets were identified by service fingerprint rather than by confirmed version detection, so version-level vulnerability is inferred rather than established for that portion of the set. And a RouterOS service observed on an internet-facing address does not by itself confirm that WebFig is the reachable service, which is the specific precondition for this vulnerability. Both caveats point the same direction: the population that needs checking is wider than the population that can be confirmed vulnerable from the outside.

Are fixes available?

Yes. MikroTik has published fixed builds across all three maintained branches: 6.49.21 on the long-term branch, 7.23.4 on the long-term branch, and 7.24.2 on the stable branch. A 7.25 beta build also carries the fix.

There is a documentation caveat worth flagging. MikroTik released the fixed builds without publishing technical detail, stating that it was withholding information to give administrators time to update. The vendor’s own advisory names neither this CVE nor WebFig, and the version-to-vulnerability mapping now in circulation comes from the CVE record and third-party analysis rather than from MikroTik. Administrators reconciling their fleet against the advisory alone will not find CVE-2026-67281 in it.

MikroTik also directs administrators to inspect devices after upgrading, checking for “Flagged” status in device logs and for scripts, user accounts, or configuration entries they do not recognize. Because a patched device can still be a previously compromised device, verify build versions and post-upgrade device state directly rather than assuming that an update closed the incident.

Until patching is confirmed, defenders should:

  • Inventory all RouterOS devices, including partner-managed and branch-site units
  • Restrict WebFig access to a dedicated management address range
  • Disable the www and www-ssl services on devices where WebFig is unused
  • Block inbound TCP/80 and TCP/443 to router management addresses at the perimeter
  • Rotate credentials held in device configuration stores after any suspected exposure
  • Review device logs for unrecognized user accounts, scripts, or scheduled tasks

How can CyCognito help your organization?

CyCognito published an Emerging Threat Advisory for CVE-2026-67281 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.

To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.


Request a free scan

See Exactly What Attackers See

Get a free scan of your attack surface and gain valuable insight into your organization's risk posture by allowing CyCognito to discover, contextualize, and test externally .

Request a Scan
Top Attack Paths