| CVE | CVE-2026-86060 |
|---|---|
| Severity | CRITICAL · CVSS 3.1 9.8 · CVSS 4.0 9.2 |
| Weakness | CWE-88 |
| Affected versions | < 6.49.21, < 7.23.4, < 7.24.2 |
| First non-vulnerable version | 6.49.21, 7.23.4, 7.24.2 (per branch) |
| Actively exploited | YES — CISA KEV catalog since 2026-09-10 |
| CISA Advisory | none |
| Published | 2026-09-05 |
What is the CVE-2026-86060 vulnerability?
This is a flaw in argument handling in the SSH login path involving usernames that start with a forbidden character. This allows modifying the trusted policy mask of RouterOS, leading to privilege escalation. The attack requires an unauthenticated SSH session to reach the RouterOS login helper.
Which RouterOS versions are vulnerable?
The vulnerable versions are those lower than 6.49.21, 7.23.4, and 7.24.2. The fixed versions are 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
Is my router at risk?
The router is exposed if the SSH service is active and reachable from untrusted networks. The vulnerability exploits the SSH server, so if this service is accessible from the Internet or external networks without adequate controls, the device is at risk.
Is the CVE-2026-86060 vulnerability actively exploited?
Yes, the vulnerability is present in the CISA KEV catalog with an addition date of 2026-09-10. ENISA reports it as exploited since 2026-09-05.
How to protect the router from CVE-2026-86060?
Update immediately to one of the fixed versions: 6.49.21, 7.23.4, or 7.24.2. Alternatively, restrict access to the SSH service only from the trusted administration network or disable it if not necessary.
Which RouterOS commands are needed to mitigate CVE-2026-86060?
Temporary mitigation: ssh service
The flaw concerns the router’s SSH server. It must be made reachable only from the administration network, or turned off if you do not use it.
/ip service print
# se SSH non serve
/ip service set ssh disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set ssh address=192.168.88.0/24
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation reboots the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2026-86060?
CVE-2026-86060 has a CVSS v3.1 score of 9.8 (CRITICAL) and a CVSS v4.0 score of 9.2 (CRITICAL).
Is authentication required to exploit CVE-2026-86060?
No, CVE-2026-86060 does not require authentication; the attack occurs via an unauthenticated SSH session.
What is the minimum version that fixes CVE-2026-86060?
The versions that fix CVE-2026-86060 are 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
Is disabling SSH enough to mitigate CVE-2026-86060?
Yes, disabling the SSH service or making it inaccessible from untrusted networks mitigates CVE-2026-86060, as the vulnerability requires access to the SSH server.
Is CVE-2026-86060 in the CISA KEV catalog?
Yes, CVE-2026-86060 is present in the CISA KEV catalog with an addition date of 2026-09-10.
Official sources
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- https://mikrotik.com/supportsec/september-2026-vulnerability/
- https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060



