Vulnerability record · CVE-2026-86060 · published 5 September 2026
CVE-2026-86060: MikroTik RouterOS SSH login argument injection privilege escalation
Mikrotik · Routeros
RouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altered. This lets an attacker escalate privileges on the router. It is remotely reachable and was fixed in 6.49.21, 7.23.4 and 7.24.2.
Description
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score is 9.2 (critical), the flaw is remotely reachable without authentication, and CISA KEV lists it with active exploitation and a short remediation deadline.
What it is
RouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altered. This lets an attacker escalate privileges on the router. It is remotely reachable and was fixed in 6.49.21, 7.23.4 and 7.24.2.
Impact
An attacker can change the trusted RouterOS policy mask and gain elevated privileges on the device, potentially taking full control of routing, firewall and management functions.
Attack surface
Reachable over the network via an unauthenticated SSH session to the RouterOS login helper; no user interaction is required. The CVSS vector shows AV:N, PR:N and UI:N, though AT:P indicates a pre-existing condition must be met.
Exploitation
Listed in CISA KEV with a 2026-09-13 remediation due date, and a public third-party write-up tagged Exploit exists. EPSS 30-day probability is about 1.06 percent (62.8th percentile), so mass scanning is not yet indicated.
What to do
- Upgrade to RouterOS 6.49.21, 7.23.4 or 7.24.2 (or later) as the vendor fix.
- If immediate patching is not possible, restrict SSH access to trusted management networks and disable SSH where it is not needed.
- Apply the mitigations in the vendor advisory and CERT Polska guidance, and follow CISA BOD 26-04 triage requirements.
- Audit RouterOS user policies and group masks for unexpected changes after exposure.
- Monitor for exploitation attempts against internet-exposed SSH management interfaces.
Detection
- Review RouterOS logs for SSH login attempts using usernames beginning with unusual or prohibited characters.
- Alert on changes to user groups, policy masks or trusted policy settings outside change windows.
- Hunt for unexpected new or modified RouterOS accounts with elevated privileges.
- Correlate SSH authentication events from external IPs with subsequent configuration changes on the device.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on 10 September 2026 as "MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 13 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve | Third Party Advisory |
| https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ | MitigationThird Party Advisory |
| https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802 | Release Notes |
| https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 | Release Notes |
| https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800 | Release Notes |
| https://mikrotik.com/supportsec/september-2026-vulnerability/ | Vendor Advisory |
| https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060 | US Government Resource |
Track CVE-2026-86060 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-86060), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.