CVE-2026-86060

CVE-2026-86060 is a critical-severity vulnerability in Mikrotik Routeros with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-09-10). The underlying weakness is classified as CWE-88.

Key facts

Description

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Frequently asked questions

What is CVE-2026-86060?
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
How severe is CVE-2026-86060?
CVE-2026-86060 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
Is CVE-2026-86060 being actively exploited?
Yes. CVE-2026-86060 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-09-10, which means active exploitation has been confirmed. It should be prioritised for remediation.
What products are affected by CVE-2026-86060?
CVE-2026-86060 affects Mikrotik Routeros. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-86060?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
When was CVE-2026-86060 published?
CVE-2026-86060 was published on 2026-09-05 and last updated on 2026-09-11.

References

Affected products (1)

More vulnerabilities in Mikrotik Routeros

All CVEs affecting Mikrotik Routeros →

Other CWE-88 (Argument Injection) vulnerabilities

Browse all CWE-88 (Argument Injection) vulnerabilities →

Threat intelligence

Threat-intel indicators referencing this CVE: