CVE-2026-86060 is a critical (CVSS 9.2) argument injection vulnerability in the SSH login path of MikroTik RouterOS. An unauthenticated attacker can supply a crafted username beginning with a prohibited character to manipulate the RouterOS trusted policy mask, achieving privilege escalation and full device compromise. It is actively exploited in the wild and listed in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-05
Added to CISA KEV: 2026-09-10 5 DAYS BETWEEN CVE AND KEV
CVE-2026-86060 is a critical argument injection vulnerability affecting MikroTik RouterOS, specifically involving an improper neutralization of argument delimiters within the SSH login path. The flaw is triggered when an SSH connection is attempted using a username that begins with a prohibited character, leading to a command injection state. This vulnerability is highly dangerous because it allows unauthenticated attackers to achieve privilege escalation and potentially gain full control over the affected router, making it a severe risk for any internet-facing device.
Details Source: Mitre, NVD Published: 2026-09-06 Updated: 2026-09-11 Named Vulnerability: MikroTrick Known Exploited Vulnerability (KEV) Risk Information CVSS v2 Base Score: 10…
If an upgrade cannot be applied immediately, disable the SSH service until the vulnerability is patched. Restrict SSH access to the device by allowing only trusted IP addresses through firewall or access‑control rules. Generated by OpenCVE AI on September 11, 2026 at 06:54 UTC.
Description CVE-2026-86060 is a critical argument injection vulnerability in MikroTik RouterOS that lets an unauthenticated attacker escalate privileges on the router.
CVE-2026-86060 (also CVSS 9.2) is a privilege escalation flaw in how RouterOS handled SSH usernames beginning with a disallowed character ...
MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.