CVE-2026-86060
SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
| CWE | CWE-88 |
| Vendor | mikrotik |
| Product | routeros |
| Published | Sep 5, 2026 |
| Last Updated | Sep 11, 2026 |
⚠️ Actively Exploited — Act Now
Get instant alerts for mikrotik routeros
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-86060.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Mikrotik / RouterOS
7.24 < 7.24.2 7.0.0 < 7.23.4 6.0.0 < 6.49.21
References
cert.pl: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve cert.pl: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ npratley.net: https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/ mikrotik.com: https://mikrotik.com/supportsec/september-2026-vulnerability/ forum.mikrotik.com: https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802 forum.mikrotik.com: https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801 forum.mikrotik.com: https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060
Credits
Sławomir Rozbicki (CERT.PL)