MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS SSH login path argument flaw allows unauthenticated privilege escalation. CVSS 9.8 (critical), CISA KEV deadline September 13, 2026.
- Vendor
- MikroTik
- Product
- RouterOS
- CVSS
- 9.8
- EPSS (exploit probability)
- 1.8%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
An unauthenticated SSH session to RouterOS’s login helper can trigger privilege escalation. When a username begins with a prohibited character, RouterOS’s argument-handling logic fails to enforce the trusted policy mask correctly, allowing an attacker to change that mask and escalate privileges.
CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, 2026. Federal agencies must remediate by September 13, 2026. Per the NVD entry, fixes are in RouterOS 6.49.21, 7.23.4 (Long-term), and 7.24.2 (Stable). Update to your channel’s current fixed version.
