CVE-2026-86060
MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Affected
- mikrotik/routeros
between 6.0..6.49.21 - mikrotik/routeros
between 7.0..7.23.4 - mikrotik/routeros
between 7.24..7.24.2
Response & Mitigation
Why act now?
Prioritisation rationale
CVE-2026-86060 reached the CISA KEV list because exploitation requires no prior authentication — an attacker only needs an unauthenticated SSH session to the RouterOS login helper to manipulate the trusted policy mask and escalate privileges. MikroTik RouterOS is widely deployed across European KRITIS environments including ISPs, industrial networks, and public-sector organisations, making the aggregate attack surface significant. The current EPSS score of 0.40 % (40th percentile) is moderate but is likely to rise sharply once public proof-of-concept code circulates, so the patch window is short. Organisations with SSH-exposed RouterOS devices on internet-facing edges or in production networks lacking management segmentation should treat this as a critical finding and schedule patching within 24 hours; the absence of a CISA ransomware-campaign flag reflects the observed attack profile to date, not a lower inherent risk.
Runbook · Step 1
Immediate response (0-24 h)
- Apply the vendor patch (highest priority): Upgrade RouterOS to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable) — choose the correct channel for your deployment. The patch is available from MikroTik; verify the exact build in the official MikroTik changelog and vendor advisory.
- Restrict SSH access immediately: Lock TCP/22 on all RouterOS devices to an explicit management source-IP allowlist (
/ip firewall filter add chain=input protocol=tcp dst-port=22 src-address-list=!mgmt-whitelist action=drop). Unauthenticated reachability of the SSH login helper is the prerequisite for exploitation. - Identify exposed devices: Audit your asset inventory for all RouterOS instances reachable via SSH from untrusted networks (internet, DMZ, guest VLANs). Run a Shodan/Censys query against your own IP ranges using
port:22 os:"RouterOS"to find externally visible devices. - Disable SSH where not required: On devices that do not need remote SSH management, run
/ip service disable ssh. Use Winbox (TCP/8291) or an out-of-band console as an interim access method. - Audit user groups and policy masks: After patching, review all RouterOS user groups and their policy masks (
/user group print detail). Any unexpected expansion of the trusted policy is a strong indicator of pre-patch exploitation. - Preserve logs before rebooting: Export RouterOS system logs (
/log print) and SSH connection records and forward them to your SIEM or log management platform to retain forensic evidence.
Runbook · Step 2
Mitigation layers
- Network segmentation: Expose management interfaces (SSH, Winbox, WebFig) exclusively via a dedicated out-of-band management VLAN. No direct internet path to TCP/22 on any router should exist.
- IPS/firewall signature: Configure a Suricata or Snort rule to alert on SSH connections to RouterOS devices where the supplied username begins with a prohibited special character (e.g.
-,+,@). Match onssh.usernamestarting with[^a-zA-Z0-9_]; set to drop in inline IPS mode once false-positive rate is validated. - RouterOS connection rate-limiting:
/ip firewall filter add chain=input protocol=tcp dst-port=22 connection-state=new limit=3,5:packet action=accept— limits the rate of new SSH sessions and reduces the window for automated exploitation attempts. - Least privilege / IAM hardening: Reduce all RouterOS user accounts to the minimum required policy rights. No account should hold
sensitiveorrebootpolicy unless operationally justified. Rename or disable the defaultadminaccount. - Public-key-only SSH authentication: Disable password-based SSH login (
/ip ssh set always-allow-password-login=no). This reduces the attack surface because the vulnerable login helper is invoked during the password-authentication flow. - Configuration change monitoring: Schedule daily automated exports (
/export) and diff them against the previous baseline. Any deviation in/user groupor/ip servicesections outside an approved change window should trigger an incident ticket.
Runbook · Step 3
Detection rules
- Network telemetry (Zeek/Suricata): Alert on SSH connections to RouterOS devices (TCP/22) where the handshake terminates abnormally or where the supplied username has zero length or begins with a non-alphanumeric character. Zeek field:
ssh.auth_attempts > 0 AND ssh.client NOT IN known_clients. - RouterOS syslog: Watch for
login failureorpolicyandchangedentries in combination with unknown source IPs. RouterOS logs policy changes under topicsystem. SPL snippet:index=network sourcetype=mikrotik "policy" "changed" | stats count by src_ip, user. - Sigma rule shape:
title: MikroTik RouterOS SSH Policy Escalation/logsource: product: mikrotik/detection: keywords: ["policy mask", "trusted", "login"]— apply against syslog forwarded from the router into your SIEM. - Downstream host indicators: Monitor hosts behind affected routers for lateral-movement signals — unexpected new routes, ARP anomalies, or traffic redirection events correlated in time with SSH sessions to the router.
- Configuration integrity check: Automate comparison of
/user group print detailoutput via Ansible or RANCID; raise an alert on any policy-mask change occurring outside a defined change window.
Description
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Affected operating systems
other
mikrotik / routeros
Metrics
Show all metrics
Weakness classes (CWE)
CWE-88Base
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
cwe.mitre.org →
Public exploit references
Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.
References & sources
- https://cert.pl/en/posts/2026/09/mikrotik-routeros-cveeuvd
- https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/euvd
- https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/euvd
- https://mikrotik.com/supportsec/september-2026-vulnerability/euvd
- https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802euvd
- https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801euvd
- https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800euvd
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060government-resource
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-11 12:52 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CPE Configuration: OR *cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.49.21 *cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* versions from (including) 7.0 up to (excluding) 7.23.4 *cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* versions from (including) 7.24 up to (excluding) 7.24.2
- Reference Type: CERT.PL: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve Types: Third Party Advisory
- Reference Type: CERT.PL: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ Types: Mitigation, Third Party Advisory
- CVE Modified2026-09-11 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-86060","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-86060","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE CISA KEV Update2026-09-10 22:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
- Date Added: 2026-09-10
- Due Date: 2026-09-10
- Required Action: 2026-09-10
- Vulnerability Name: 2026-09-10
- CVE Modified2026-09-10 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060
- SSVC: {"id":"CVE-2026-86060","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-86060","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
- CVE Modified2026-09-09 05:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-86060","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-86060","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…