CVE-2026-86060
CVE-2026-86060 is a critical-severity vulnerability in Mikrotik Routeros with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-09-10). The underlying weakness is classified as CWE-88.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v4: 9.2
- EPSS exploit prediction: 1% (63rd percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2026-09-10)
- Weakness: CWE-88
- Affected product: Mikrotik Routeros
- Published:
- Last modified:
Description
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Frequently asked questions
- What is CVE-2026-86060?
- RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- How severe is CVE-2026-86060?
- CVE-2026-86060 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-86060 being actively exploited?
- Yes. CVE-2026-86060 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-09-10, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2026-86060?
- CVE-2026-86060 affects Mikrotik Routeros. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-86060?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- When was CVE-2026-86060 published?
- CVE-2026-86060 was published on 2026-09-05 and last updated on 2026-09-11.
References
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- https://mikrotik.com/supportsec/september-2026-vulnerability/
- https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060
Affected products (1)
- cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
More vulnerabilities in Mikrotik Routeros
- CVE-2017-20149 — Critical (CVSS 9.8): The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka…
- CVE-2022-34960 — Critical (CVSS 9.8): The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic…
- CVE-2018-7445 — Critical (CVSS 9.8): A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages.…
- CVE-2023-30799 — Critical (CVSS 9.1): MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A…
- CVE-2018-14847 — Critical (CVSS 9.1): MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated…
- CVE-2022-45313 — High (CVSS 8.8): Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This…
All CVEs affecting Mikrotik Routeros →
Other CWE-88 (Argument Injection) vulnerabilities
- CVE-2026-65770 — Critical (CVSS 10.0): Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache…
- CVE-2026-57572 — Critical (CVSS 10.0): Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted…
- CVE-2026-40281 — Critical (CVSS 10.0): Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint…
- CVE-2023-6269 — Critical (CVSS 10.0): An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify…
- CVE-2007-0882 — Critical (CVSS 10.0): Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11)…
- CVE-2004-0480 — Critical (CVSS 10.0): Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via…
Browse all CWE-88 (Argument Injection) vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 192.158.15.201 (ipv4-addr)
- 190.228.33.44 (ipv4-addr)
- 177.234.234.88 (ipv4-addr)
- 110.235.240.223 (ipv4-addr)
- 109.245.231.73 (ipv4-addr)
- 103.153.63.146 (ipv4-addr)
- 103.110.109.53 (ipv4-addr)
- 115.42.67.186 (ipv4-addr)