Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3362 articles · 210865 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-86060KEVEXPLOITEDPATCHED
mikrotik · routeros

SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

Description

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Affected Products

VendorProductVersions
mikrotikrouteros7.24, 7.0.0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
mikrotikrouteroscert_advisory90%

References

  • https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve(third-party-advisory)
  • https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/(technical-description)
  • https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/(exploit)
  • https://mikrotik.com/supportsec/september-2026-vulnerability/(vendor-advisory)
  • https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802(release-notes)
  • https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801(release-notes)
  • https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800(release-notes)

Related News (3 articles)

Tier B
BSI Advisories2h ago
[NEU] [kritisch] MikroTik RouterOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
BleepingComputer2h ago
Hackers exploit new MikroTik RouterOS flaws to hijack routers
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-86060 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Login privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
7.24.27.23.46.49.21
CWECWE-88
PublishedSep 5, 2026
Trending Score105🔥
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-67277EXPKEV
Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
Trending: 105
NONECVE-2026-67276EXPKEV
SSH user impersonation possible in Mikrotik RouterOS
Trending: 105
NONECVE-2026-67278
TLS server impersonation possible in Mikrotik RouterOS
Trending: 31
NONECVE-2026-67281
Unauthenticated file read in Mikrotik RouterOS
Trending: 31
NONECVE-2026-67279
SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 5, 2026
Added to CISA KEV
Sep 5, 2026
Discovered by ZDM
Sep 5, 2026
Actively Exploited
Sep 5, 2026
Patch Available
Sep 5, 2026