## Overview
CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities (KEV) catalog on September 10, 2026. This addition signals a federal deadline for agencies to address the vulnerability. The flaw exists in MikroTik RouterOS and allows attackers to escalate privileges through an argument-handling issue in the SSH login path.
## Technical Details
The vulnerability arises when usernames begin with a prohibited character. This improper neutralization of argument delimiters can change the trusted RouterOS policy mask. Exploitation requires an unauthenticated SSH session to access the RouterOS login helper. The flaw has a CVSS score of 9.2, indicating high severity. The affected versions include RouterOS prior to 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
## Impact
Successful exploitation allows attackers to modify the RouterOS policy mask, leading to privilege escalation. This could enable unauthorized access to sensitive network configurations and data. Given the ease of exploitation, organizations using affected RouterOS versions are at significant risk.
## Mitigation
Defenders should upgrade to the patched versions of RouterOS immediately: 6.49.21, 7.23.4, or 7.24.2. Regularly review and apply security updates to maintain protection against known vulnerabilities. Additionally, limit SSH access to trusted networks and monitor logs for any unauthorized access attempts.
CSURFACE Threat Sensor