CVE-2026-86060
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- Published Sep 5, 2026
- CVSS 9.2 critical
- 6.4% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
- A fix is available
Affected software
In the news
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS BleepingComputer ·
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild The Hacker News ·
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key The Hacker News ·
- Multiple Vulnerabilities in Mikrotik Routers Could Allow for Admin Hijacking CIS MS-ISAC ·
- Mikrotik security advisory (AV26-887) – Update 2 Canadian Centre for Cyber Security ·