CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on 2026-09-10, confirming active exploitation of a high-severity argument-handling flaw in MikroTik RouterOS that lets unauthenticated attackers escalate privileges over SSH.
What Is It
CVE-2026-86060 is an improper neutralization of argument delimiters in a command (CWE-88) affecting MikroTik RouterOS. The flaw sits in the SSH login path and involves usernames that begin with a prohibited character. By abusing that argument handling, an attacker can alter the trusted RouterOS policy mask, resulting in privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.
CERT Polska ([email protected]) assigned the CVSS 4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H, which computes to a base score of 8.7 (HIGH). The AT:P metric, attack requirements present, is what holds the score below the critical range despite the high confidentiality, integrity, and availability impacts. The CVE was published 2026-09-05 and remains in "Awaiting Analysis" status at NVD.
Why It Matters
KEV inclusion confirms exploitation in the wild. CISA's SSVC decision points for this CVE record exploitation as active, automatable as yes, and technical impact as total: meaning attackers can script this against exposed devices at scale and fully compromise them. Network attack vector with no privileges and no user interaction required means any RouterOS device with SSH reachable from an untrusted network is a candidate target. Known ransomware campaign use is listed as Unknown.
Treat the base score as a floor, not a ceiling, for prioritization here: a HIGH-rated bug with confirmed in-the-wild exploitation and automatable delivery outranks an unexploited CRITICAL on any risk-based patching queue.
What's Vulnerable
MikroTik RouterOS across all three release trains:
- 6.0.0 up to (not including) 6.49.21
- 7.0.0 up to (not including) 7.23.4
- 7.24 up to (not including) 7.24.2
Patch Status
Fixed in RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. This entry is flagged for forensic triage. The due date is 2026-09-13: three days after KEV addition.
Sources
- CISA Known Exploited Vulnerabilities Catalog; CVE-2026-86060
- NVD, CVE-2026-86060
- MikroTik; September 2026 Vulnerability
- CERT Polska, Vulnerabilities in MikroTik RouterOS Actively Exploited, primary CERT Polska advisory for this CVE
- CERT Polska, MikroTik RouterOS CVE, unversioned short slug pointing at the same September 2026 RouterOS advisory above; cite the full advisory URL in preference to this one
- MikroTik Forum, 6.49.21 Long-term released
- MikroTik Forum, 7.23.4 Long-term released
- MikroTik Forum, 7.24.2 Stable released
- CISA BOD 26-04; Prioritizing Security Updates Based on Risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements