← All Advisories

CVE-2026-86060: MikroTik RouterOS Improper

Status: KEV  |  Advisory ID: CVE-2026-86060

Key Details

CVECVE-2026-86060
CVSSCVSS 9.8 (Critical): attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected productsMikroTik RouterOS
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-10.

What to Know

RouterOS contains an argument-handling flaw in the SSH login

path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-86060
Vendor advisoryhttps://mikrotik.com/supportsec/september-2026-vulnerability/