🔴 CVE-2026-86060

CVE-2026-86060 is a critical (CVSS 9.2) argument injection vulnerability in the SSH login path of MikroTik RouterOS. An unauthenticated attacker can supply a crafted username beginning with a prohibited character to manipulate the RouterOS trusted policy mask, achieving privilege escalation and full device compromise. It is actively exploited in the wild and listed in CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
9.2
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-05

Added to CISA KEV: 2026-09-10 5 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-09-14)

Summary

CVE-2026-86060 is a critical argument injection vulnerability affecting MikroTik RouterOS, specifically involving an improper neutralization of argument delimiters within the SSH login path. The flaw is triggered when an SSH connection is attempted using a username that begins with a prohibited character, leading to a command injection state. This vulnerability is highly dangerous because it allows unauthenticated attackers to achieve privilege escalation and potentially gain full control over the affected router, making it a severe risk for any internet-facing device.

Exploitation

  • Active Exploitation: The vulnerability is currently being exploited in the wild as part of a wave of attacks targeting MikroTik devices [4][8].
  • Threat Actors: While specific named threat actors are still being analyzed, the vulnerability is being leveraged in automated campaigns alongside other related flaws (such as CVE-2026-67276 and CVE-2026-67277) to hijack devices [4][6].
  • Exploit Availability: There are reports of active, functional exploits being used by attackers to gain unauthorized access [4].
  • Attack Prerequisites: The attack is network-based and does not require prior authentication from the attacker, nor does it require user interaction on the target device [3].

Affected Products & Patches

  • Affected Products: Various versions of MikroTik RouterOS that support SSH access [9].
  • Patch Availability: MikroTik has released patched versions of RouterOS across all release channels to address this vulnerability; users are urged to update their devices immediately [5].
  • Mitigations/Workarounds: If an immediate upgrade is not possible, administrators should disable the SSH service entirely or restrict SSH access to the device by allowing connections only from trusted, verified IP addresses via firewall or access-control rules [2].

Impact

  • Access/Capabilities: Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary commands, leading to privilege escalation and full unauthorized control of the router [3][7].
  • Business Risk: For internet-facing deployments, this vulnerability presents an extremely high risk, as it allows attackers to completely compromise the network infrastructure, potentially leading to unauthorized data interception, device bricking, or the integration of the router into a botnet for further malicious activity [1].

Sources

  1. CVE-2026-86060 | Tenable®

    Details Source: Mitre, NVD Published: 2026-09-06 Updated: 2026-09-11 Named Vulnerability: MikroTrick Known Exploited Vulnerability (KEV) Risk Information CVSS v2 Base Score: 10…

  2. CVE-2026-86060 - Vulnerability Details - OpenCVE

    If an upgrade cannot be applied immediately, disable the SSH service until the vulnerability is patched. Restrict SSH access to the device by allowing only trusted IP addresses through firewall or access‑control rules. Generated by OpenCVE AI on September 11, 2026 at 06:54 UTC.

  3. CVE-2026-86060 - MikroTik RouterOS Improper Neutralization of Argument ...

    Description CVE-2026-86060 is a critical argument injection vulnerability in MikroTik RouterOS that lets an unauthenticated attacker escalate privileges on the router.

  4. Hackers exploit RouterOS flaws to hijack MikroTik devices ...

    CVE-2026-86060 (also CVSS 9.2) is a privilege escalation flaw in how RouterOS handled SSH usernames beginning with a disallowed character ...

  5. September 2026 vulnerability

    MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.