Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-13 ยท updated: 2026-09-13 ยท tags: [cve, mikrotik, routeros, privilege-escalation, unauthenticated, edge-device, kev] ยท confidence: high ยท severity: critical ยท affected_sectors: [global] ยท au_impact: false

CVE-2026-86060 is a maximum-severity argument-handling flaw in MikroTik RouterOS, rated CVSS 3.1 9.8 (CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The defect sits in the SSH login path and involves usernames that begin with a prohibited character, which allows the trusted RouterOS policy mask to be changed and leads to privilege escalation; exploitation requires only that an unauthenticated SSH session reaches the RouterOS login. CISA added it to the Known Exploited Vulnerabilities catalogue on 10 September 2026 on evidence of active exploitation, describing it as improper neutralisation of argument delimiters.

Attribute Detail
CVE CVE-2026-86060
CVSS 9.8 (CVSS 3.1, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Vendor / product MikroTik โ€” RouterOS
NVD published 2026-09-05
KEV added 2026-09-10
Reported 2026-09-13