MikroTik RouterOS Vulnerability CVE-2026-86060: Early Warning
- Severity
- HIGH
- Affected component
- mikrotik routeros (npm)
- Patched version
- Not yet available
An early warning has been issued for a MikroTik RouterOS vulnerability, CVE-2026-86060, which may allow attackers to change the trusted RouterOS policy mask and achieve privilege escalation.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-86060 to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, reportedly exploited in the wild, involves improper neutralization of argument delimiters in a command, allowing potential privilege escalation. The specific version range of MikroTik RouterOS affected by this vulnerability has not been officially published yet.
CISA advises users and administrators to upgrade to the latest version of MikroTik RouterOS as a mitigation step. Additionally, reviewing and strengthening access controls is recommended to reduce the risk of privilege escalation.
What to do about it
- Upgrade to the latest version of MikroTik RouterOS.
- Review and strengthen access controls to mitigate potential privilege escalation.
- Monitor the primary sources for updates on the vulnerability and any official fixes.
How 0Day would have caught this
mikrotik routeros is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using MikroTik RouterOS, you may be affected. The specific version range has not been officially published yet.
What should I do right now?
Upgrade to the latest version of MikroTik RouterOS and review your access controls.
Has this been exploited in the wild?
Yes, this vulnerability is reportedly being exploited in the wild.