← Vulnerability feed

Vulnerability record · CVE-2026-86060 · published 5 September 2026

CVE-2026-86060: MikroTik RouterOS SSH login argument injection privilege escalation

Mikrotik · Routeros

RouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altered. This lets an attacker escalate privileges on the router. It is remotely reachable and was fixed in 6.49.21, 7.23.4 and 7.24.2.

9.2 CVSS 4.0 Critical CISA KEV since 10 Sep 2026 EPSS 1.8% · top 21.8% CWE-88 · Argument injection
9.2CVSS 4.0 base score
1.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
8References, 1 tagged exploit
11 Sep 2026Last modified by NVD

Description

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score is 9.2 (critical), the flaw is remotely reachable without authentication, and CISA KEV lists it with active exploitation and a short remediation deadline.

What it is

RouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altered. This lets an attacker escalate privileges on the router. It is remotely reachable and was fixed in 6.49.21, 7.23.4 and 7.24.2.

Impact

An attacker can change the trusted RouterOS policy mask and gain elevated privileges on the device, potentially taking full control of routing, firewall and management functions.

Attack surface

Reachable over the network via an unauthenticated SSH session to the RouterOS login helper; no user interaction is required. The CVSS vector shows AV:N, PR:N and UI:N, though AT:P indicates a pre-existing condition must be met.

Exploitation

Listed in CISA KEV with a 2026-09-13 remediation due date, and a public third-party write-up tagged Exploit exists. EPSS 30-day probability is about 1.06 percent (62.8th percentile), so mass scanning is not yet indicated.

What to do

  • Upgrade to RouterOS 6.49.21, 7.23.4 or 7.24.2 (or later) as the vendor fix.
  • If immediate patching is not possible, restrict SSH access to trusted management networks and disable SSH where it is not needed.
  • Apply the mitigations in the vendor advisory and CERT Polska guidance, and follow CISA BOD 26-04 triage requirements.
  • Audit RouterOS user policies and group masks for unexpected changes after exposure.
  • Monitor for exploitation attempts against internet-exposed SSH management interfaces.

Detection

  • Review RouterOS logs for SSH login attempts using usernames beginning with unusual or prohibited characters.
  • Alert on changes to user groups, policy masks or trusted policy settings outside change windows.
  • Hunt for unexpected new or modified RouterOS accounts with elevated privileges.
  • Correlate SSH authentication events from external IPs with subsequent configuration changes on the device.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on 10 September 2026 as "MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 13 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-86060 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-7445MikroTik RouterOS SMB pre-auth buffer overflow enabling code executionMikroTik RouterOS contains a stack-based buffer overflow in its SMB service when handling NetBIOS session request messages. The overflow occurs befor…KEVEPSS 61%analysed9.1CVE-2018-14847MikroTik RouterOS WinBox directory traversal allows file read and writeMikroTik RouterOS through 6.42 contains a directory traversal flaw in the WinBox interface. Unauthenticated remote attackers can read arbitrary files…KEVEPSS 96%analysed8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed6.9CVE-2026-67279Mikrotik routeros vulnerabilityRouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthent…KEVEPSS 1.0%9.8CVE-2022-45315Mikrotik routeros out-of-bounds read vulnerabilityMikrotik RouterOs before stable v7.6 was discovered to contain an out-of-bounds read in the snmp process. This vulnerability allows authenticated att…EPSS 1.3%9.8CVE-2017-20149Mikrotik routeros out-of-bounds write vulnerabilityThe Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthe…EPSS 2.0%9.8CVE-2022-34960Mikrotik routeros link following vulnerabilityThe container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations …EPSS 1.5%9.2CVE-2026-67276Mikrotik routeros improper verification of cryptographic signature vulnerabilityRouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type an…EPSS 6.5%

Source: NIST National Vulnerability Database (record CVE-2026-86060), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.