| CVE | CVE-2026-67281 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 · CVSS 4.0 8.7 |
| Weakness | CWE-22, CWE-824 |
| Affected versions | < 7.23.4, < 7.24.2 |
| First non-vulnerable version | 7.23.4, 7.24.2 (per branch) |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2026-09-05 |
What is the CVE-2026-67281 vulnerability?
The vulnerability resides in the /jsproxy path of WebFig, where a newly allocated session retains an uninitialized pointer used for file authorization. An unauthenticated attacker can manipulate the allocation so that the file service path dereferences this pointer with sufficient privileges, then provides parent directory components in an encrypted URI to escape the WebFig namespace and disclose root-owned files, including configuration stores containing credentials.
Which RouterOS versions are vulnerable?
The vulnerable versions are all those lower than 7.23.4 and lower than 7.24.2. The fixed versions are 7.23.4 (Long-term) and 7.24.2 (Stable).
Is my router at risk?
A router is exposed if the WebFig service is active and reachable from untrusted networks. If WebFig is not used, it must be disabled; if it is used, it must be accessible exclusively from the internal administration network.
Is the CVE-2026-67281 vulnerability actively exploited?
As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and ENISA does not report it as exploited.
How to protect the router from CVE-2026-67281?
Update RouterOS to version 7.23.4 (Long-term) or 7.24.2 (Stable). Alternatively, disable access to WebFig if not necessary, or limit its reachability exclusively to the trusted administration network.
Which RouterOS commands are needed to mitigate CVE-2026-67281?
Temporary mitigation: www service
The defect concerns the web management service (WebFig). If you do not use it, turn it off; if you do use it, it must be reachable only from the administration network.
# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation reboots the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2026-67281?
CVE-2026-67281 has a CVSS v3.1 score of 7.5 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH).
Which weaknesses (CWE) are associated with CVE-2026-67281?
CVE-2026-67281 is associated with CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)) and CWE-824 (Access of Uninitialized Pointer).
Is authentication required to exploit CVE-2026-67281?
No, CVE-2026-67281 is an unauthenticated vulnerability: an attacker can exploit it without valid credentials.
Which RouterOS versions fix CVE-2026-67281?
CVE-2026-67281 is fixed in versions 7.23.4 (Long-term) and 7.24.2 (Stable).
Official sources
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- https://mikrotik.com/supportsec/september-2026-vulnerability/
- https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/



