CVE-2026-86060

Published Sep 5, 2026

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-86060 is an argument-handling flaw identified in MikroTik RouterOS, specifically within its SSH login path. This vulnerability arises when usernames begin with a prohibited character, which can be manipulated to alter the trusted RouterOS policy mask. Such a change ultimately leads to privilege escalation within the system. Exploitation of CVE-2026-86060 requires an unauthenticated SSH session to successfully reach the RouterOS login helper. This flaw is often discussed in conjunction with CVE-2026-67276, an SSH authentication bypass, as chaining these two vulnerabilities can allow an attacker to gain full, unauthenticated control over affected MikroTik devices. MikroTik has released fixes for this issue in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

Description
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Source
cvd@cert.pl
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

cvd@cert.pl
CWE-88

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

11

  1. 🚨 Upozorňujeme na kritické zranitelnosti v RouterOS v zařízeních MikroTik, CVE-2026-67277, CVE-2026-86060, CVE-2026-67276. Zranitelnosti umožňují vzdálené spuštění kódu s administrátorskými oprávněními prostřednictvím služby SSH, přičemž exploit zcel

    @GOVCERT_CZ

    8 Sept 2026

    143 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Fallos en MikroTik RouterOS (cadena “MikroTrick”) Varios CVEs (entre ellos CVE-2026-67276 y CVE-2026-86060) que, encadenados, permiten tomar control de routers con SSH expuesto. CERT Polska y otros reportaron explotación activa. https://t.co/vddbaJMrke

    @CyberVoyager8

    7 Sept 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. MikroTrick: CVE-2026-67276 + CVE-2026-86060. CERT Polska: full MikroTik RouterOS admin via exposed SSH. Patch 7.24.2 / 7.23.4 / 6.49.21. #cybersecurity #infosec #MikroTik #RouterOS #threatintel https://t.co/E97CAs2eH5

    @Caldura7

    7 Sept 2026

    41 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-67276 (CVSS 9.2): MikroTik RouterOS SSH auth-bypass was exploited as a zero-day before patches shipped, enabling full router takeover when chained with CVE-2026-86060. Active exploitation confirmed: - CVE-2026-67276 (CWE-347) lets an attacker authenticate via SSH as ht

    @DFIR_Radar

    7 Sept 2026

    188 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CVE-2026-67276 (SSH auth bypass) chained with CVE-2026-86060 (SSH privilege escalation) lets attackers own MikroTik routers with no private key. Hunt logs for "login failure for user -2" and flag any "ops" account. #DFIR_Radar https://t.co/VQ8jOEjDcu

    @DFIR_Radar

    7 Sept 2026

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Warning: Critical MikroTik RouterOS is under active exploitation. CVE-2026-67276 CVSS 9.2 & CVE-2026-86060 CVSS 9.2. Attackers are chaining SSH Auth Bypass and PrivEsc to seize full admin control of internet-exposed devices. #Patch #Patch #Patch

    @CCBalert

    7 Sept 2026

    238 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. MikroTik RouterOS CVE-2026-67279 + CVE-2026-86060, #pruva reproduced the chain: 1. CVE-2026-67279 provided the unauthenticated SSH session/exec path. 2. CVE-2026-86060 used the -2 identity/trusted-field behavior to obtain privileged RouterOS operations. https://t.co/DFKklxYBfe

    @pruvadev

    7 Sept 2026

    1230 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  8. Actively exploited 0-day chain targeting MikroTik routers.If your RouterOS SSH is exposed to the internet, you are vulnerable to a full admin takeover via the "MikroTrick" exploit (CVE-2026-67276 & CVE-2026-86060). ~122,500 routers are currently sitting ducks.Patch immediatel

    @Orion84x

    7 Sept 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. 🔴 MikroTrick — MikroTik routers under active attack Attackers are exploiting CVE-2026-67276 + CVE-2026-86060 against Internet-exposed RouterOS devices. The chain https://t.co/RSJXdyWeNL #CVE #CVE202667276 #CVE202686060 #MikroTik #RouterOS #MikroTrick #CyberSecurity #Info

    @stem__shop

    6 Sept 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. MikroTrick zero-day chain gives unauthenticated attackers admin control of MikroTik RouterOS via internet-exposed SSH (CVE-2026-67276 CVSS 9.2 + CVE-2026-86060). Patch and block WAN SSH now. #MikroTik #ZeroDay #CyberSecurity https://t.co/adE7FghxsF

    @CyberWorldOps

    6 Sept 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. It took us 3 hours to rewrite the full pre-auth RCE MikroTrick chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) from the public advisory. https://t.co/4tmLd8aAFq

    @TolmoHQ

    6 Sept 2026

    4291 Impressions

    12 Retweets

    27 Likes

    17 Bookmarks

    5 Replies

    2 Quotes

  12. CVE-2026-86060 (CVSS 9.2) impacts MikroTik RouterOS SSH login, allowing policy changes. Review affected devices and apply updates. https://t.co/VnxpRzX34v via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/MyR2izbmjv

    @ADKCyber

    6 Sept 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE Record: CVE-2026-86060 https://t.co/1nHruRsea8

    @Mas73r

    6 Sept 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. A severe vulnerability was disclosed for Mikrotik RouterOS (CVE-2026-86060) https://t.co/vyUW8mN8Ks

    @vuldb

    6 Sept 2026

    228 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes