An unauthenticated file read flaw in MikroTik RouterOS WebFig lets a remote attacker traverse out of the web namespace and read root-owned configuration files, including stored credentials.
Read more about Emerging Threat: (CVE-2026-67281) MikroTik RouterOS Unauthenticated File Read via WebFig