🔐 CVE Alert

CVE-2026-86060

UNKNOWN 0.0 ⚠️ CISA KEV

SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

CWE CWE-88
Vendor mikrotik
Product routeros
Published Sep 5, 2026
Last Updated Sep 11, 2026
⚠️ Actively Exploited — Act Now

Get instant alerts for mikrotik routeros

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-86060.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Mikrotik / RouterOS
7.24 < 7.24.2 7.0.0 < 7.23.4 6.0.0 < 6.49.21

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve cert.pl: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ npratley.net: https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/ mikrotik.com: https://mikrotik.com/supportsec/september-2026-vulnerability/ forum.mikrotik.com: https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802 forum.mikrotik.com: https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 forum.mikrotik.com: https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060

Credits

Sławomir Rozbicki (CERT.PL)