type: cve ยท created: 2026-09-13 ยท updated: 2026-09-13 ยท tags: [cve, mikrotik, routeros, privilege-escalation, unauthenticated, edge-device, kev] ยท confidence: high ยท severity: critical ยท affected_sectors: [global] ยท au_impact: false
CVE-2026-86060 is a maximum-severity argument-handling flaw in MikroTik RouterOS, rated CVSS 3.1 9.8 (CRITICAL, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The defect sits in the SSH login path and involves usernames that begin with a prohibited character, which allows the trusted RouterOS policy mask to be changed and leads to privilege escalation; exploitation requires only that an unauthenticated SSH session reaches the RouterOS login. CISA added it to the Known Exploited Vulnerabilities catalogue on 10 September 2026 on evidence of active exploitation, describing it as improper neutralisation of argument delimiters.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-86060 |
| CVSS | 9.8 (CVSS 3.1, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Vendor / product | MikroTik โ RouterOS |
| NVD published | 2026-09-05 |
| KEV added | 2026-09-10 |
| Reported | 2026-09-13 |