CVE-2026-86060
published 2026-09-05CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS…
PriorityP188critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-09-13
Exploited in the wild
EPSS
6.39%
93.5th percentile
RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mikrotik | routeros | >= 6.0 < 6.49.21 | 6.49.21 |
| mikrotik | routeros | >= 6.0.0 < 6.49.21 | 6.49.21 |
| mikrotik | routeros | >= 7.0 < 7.23.4 | 7.23.4 |
| mikrotik | routeros | >= 7.0.0 < 7.23.4 | 7.23.4 |
| mikrotik | routeros | >= 7.24 < 7.24.2 | 7.24.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.2CRITICAL
cisa9.2CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
cisa·2026-09-25·CVSS 6.5
CVE-2026-67279 [MEDIUM] CWE-841 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Vulnerability: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Affected: MikroTik RouterOS
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible
CISA
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
cisa·2026-09-10·CVSS 9.2
CVE-2026-86060 [CRITICAL] CWE-88 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Vulnerability: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Affected: MikroTik RouterOS
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensu
VulDB
Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Login privileges management (EUVD-2026-72029)
vuldb·2026-09-05·CVSS 9.2
CVE-2026-86060 [CRITICAL] Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Login privileges management (EUVD-2026-72029)
A vulnerability has been found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 and classified as very critical. Affected by this issue is some unknown functionality of the component SSH Login. This manipulation causes improper privilege management.
This vulnerability is tracked as CVE-2026-86060. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to pr
ghsa_unreviewed·2026-09-05
CVE-2026-86060 [CRITICAL] CWE-88 RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to pr
RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
VulnCheck
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
vulncheck·2026·CVSS 9.2
CVE-2026-86060 [CRITICAL] MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected: MikroTik RouterOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-explo
No detection rules found.
Hackernews
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
blogs_hackernews·2026-09-26·CVSS 8.8
CVE-2026-65660 [HIGH] SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows -
CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
CVE-2026-67279 (CVSS score: 6.9) - An improper enforcement of behavioral workflow vulnerabilit
Hackernews
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
blogs_hackernews·2026-09-23·CVSS 6.9
CVE-2026-67279 [MEDIUM] MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.
The chain, which CERT Polska calls MikroTrick , combines an SSH state-machine flaw ( CVE-2026-67279 ) with an argument-injection bug in the RouterOS login process ( CVE-2026-86060 ). Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2.
As previously reported , CERT Polska warned o
Checkpoint
14th September – Threat Intelligence Report
blogs_checkpoint·2026-09-14·CVSS 10.0
CVE-2026-72898 [CRITICAL] 14th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with t
Hackernews
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
blogs_hackernews·2026-09-12·CVSS 8.8
CVE-2026-42016 [HIGH] CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect , and MikroTik RouterOS to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation in the wild.
Details of the vulnerabilities are as follows -
CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's s
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
https://cert.pl/en/posts/2026/09/mikrotik-routeros-cvehttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800https://mikrotik.com/supportsec/september-2026-vulnerability/https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060
2026-09-05
Published
2026-09-10
Added to CISA KEV
Exploited in the wild