THREAT OPS › CVEs › CVE-2026-86060
CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Vulnerability details
- Affected productsRouterOS
- KEV remediation due2026-09-13
Related reporting
- 14th September – Threat Intelligence Reportcheckpoint_research
- AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060cccs_ca
- [CISA KEV] CVE-2026-86060 — MikroTik RouterOS: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerabilitycisa_kev
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories
- Mikrotik security advisory (AV26-887)cccs_ca
- MikroTik router flaws allow takeover without a passwordmalwarebytes_blog
- MicroTik Routers Under Attack in New Campaignduo_decipher
- [NVD] CVE-2026-86060 — RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reacnvd