Skip to content

CVE-2026-86060

MikroTik RouterOS SSH username flaw enables privilege escalation (CVE-2026-86060)

Critical 9.2 KEV Published · Updated

MikroTik RouterOS has a critical SSH login flaw, CVE-2026-86060, that allows an unauthenticated attacker to escalate privileges. CISA KEV lists the flaw as exploited. Upgrade to RouterOS 6.49.21, 7.23.4 or 7.24.2 and restrict SSH exposure.

What happened

RouterOS contains a flaw in the SSH login path. The SSH login helper mishandles usernames that begin with a prohibited character. An unauthenticated attacker who can reach the SSH service over the network can send such a crafted username and change the trusted RouterOS policy mask, leading to privilege escalation. No prior credentials are required.

The CVSS v4.0 score is 9.2, rated critical, with high impact on confidentiality, integrity and availability. CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on 10 September 2026 with a required action due date of 13 September 2026. CISA's SSVC assessment also marks exploitation as active.

Who is affected

Affected versions are RouterOS 7.24 to before 7.24.2, 7.0.0 to before 7.23.4, and 6.0.0 to before 6.49.21. RouterOS runs on MikroTik devices, and the vulnerable component is the SSH login path used for remote administration. Organisations that expose SSH on these devices to the internet or to untrusted networks should treat this as critical. Devices already upgraded to RouterOS 6.49.21, 7.23.4 or 7.24.2 are fixed.

What to do now

  1. Upgrade affected devices as soon as possible. The fixed builds are RouterOS 7.24.2 (Stable), 7.23.4 (Long-term) and 6.49.21 (Long-term). Choose the appropriate branch for each device.
  2. If a fixed build cannot be applied immediately, restrict or disable SSH access from untrusted networks. Permit management only from trusted networks or out-of-band access.
  3. Identify every internet-facing RouterOS device and verify its version. CISA's KEV required action due date was 13 September 2026, so unpatched internet-facing devices should be treated as urgent.
  4. If neither patching nor restricting SSH is possible, discontinue use of the product for internet-facing functions until remediation.

How to detect it

The CVE record does not provide vendor-specific indicators of compromise. Because the vulnerability is reached through the SSH login path, start by identifying RouterOS devices with SSH reachable from untrusted networks. If logging is available, review SSH authentication logs for login attempts involving crafted usernames, and check for unexpected changes to trusted RouterOS policy masks, which the vulnerability can alter.

Beyond the patch

This flaw is a reminder that an unauthenticated network service is measurable exposure. Virtual CISO Services can help map and close exposed management ports such as SSH on RouterOS devices. Because CISA KEV lists the flaw as exploited, Managed Detection & Response is appropriate for determining whether a recently exposed device was used, and Incident Response Retainer provides support if compromise is suspected.

Affected and fixed versions

ProductAffectedFixed in
RouterOS7.24 – < 7.24.2
7.0.0 – < 7.23.4
6.0.0 – < 6.49.21
7.24.2
7.23.4
6.49.21

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.