Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-86060

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS SSH login path argument flaw allows unauthenticated privilege escalation. CVSS 9.8 (critical), CISA KEV deadline September 13, 2026.

cat cve-2026-86060.json
Vendor
MikroTik
Product
RouterOS
CVSS
9.8
EPSS (exploit probability)
1.8%
Status
kev
CISA patch-by (BOD 22-01)
Published

An unauthenticated SSH session to RouterOS’s login helper can trigger privilege escalation. When a username begins with a prohibited character, RouterOS’s argument-handling logic fails to enforce the trusted policy mask correctly, allowing an attacker to change that mask and escalate privileges.

CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on September 10, 2026. Federal agencies must remediate by September 13, 2026. Per the NVD entry, fixes are in RouterOS 6.49.21, 7.23.4 (Long-term), and 7.24.2 (Stable). Update to your channel’s current fixed version.