Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-86060 2026-09-10

MikroTik RouterOS CVE-2026-86060: Unauthenticated SSH Flaw Grants Privilege Escalation, Now in CISA KEV

"CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on 2026-09-10, confirming active exploitation of a high-severity argument-handling flaw in MikroTik RouterOS that lets unauthenticated attackers…"

CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on 2026-09-10, confirming active exploitation of a high-severity argument-handling flaw in MikroTik RouterOS that lets unauthenticated attackers escalate privileges over SSH.

What Is It

CVE-2026-86060 is an improper neutralization of argument delimiters in a command (CWE-88) affecting MikroTik RouterOS. The flaw sits in the SSH login path and involves usernames that begin with a prohibited character. By abusing that argument handling, an attacker can alter the trusted RouterOS policy mask, resulting in privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.

CERT Polska ([email protected]) assigned the CVSS 4.0 vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H, which computes to a base score of 8.7 (HIGH). The AT:P metric, attack requirements present, is what holds the score below the critical range despite the high confidentiality, integrity, and availability impacts. The CVE was published 2026-09-05 and remains in "Awaiting Analysis" status at NVD.

Why It Matters

KEV inclusion confirms exploitation in the wild. CISA's SSVC decision points for this CVE record exploitation as active, automatable as yes, and technical impact as total: meaning attackers can script this against exposed devices at scale and fully compromise them. Network attack vector with no privileges and no user interaction required means any RouterOS device with SSH reachable from an untrusted network is a candidate target. Known ransomware campaign use is listed as Unknown.

Treat the base score as a floor, not a ceiling, for prioritization here: a HIGH-rated bug with confirmed in-the-wild exploitation and automatable delivery outranks an unexploited CRITICAL on any risk-based patching queue.

What's Vulnerable

MikroTik RouterOS across all three release trains:

Patch Status

Fixed in RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. This entry is flagged for forensic triage. The due date is 2026-09-13: three days after KEV addition.

Sources