DIRAS TAKE
Urgent — CISA added this CVE to its Known Exploited Vulnerabilities catalog with a rapid remediation due date, so prioritize patching or mitigating internet-exposed RouterOS SSH services immediately.
What is CVE-2026-86060?
An unauthenticated attacker can manipulate the SSH login flow on MikroTik RouterOS to alter the device's trusted policy mask and gain elevated privileges; this is tracked as CVE-2026-86060. The flaw affects RouterOS releases 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2. Exploitation requires only that the attacker reach the RouterOS SSH login helper (network access to SSH), no account or user interaction is required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of MikroTik RouterOS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.24 – before 7.24.2 | 7.24.2 |
| 7.x | 7.0.0 – before 7.23.4 | 7.23.4 |
| 6.x | 6.0.0 – before 6.49.21 | 6.49.21 |
Is CVE-2026-86060 being exploited?
CISA added CVE-2026-86060 to the Known Exploited Vulnerabilities catalog on 2026-09-10, and U.S. federal agencies must remediate by 2026-09-13; public exploit code is also available.
How to fix CVE-2026-86060
- Upgrade RouterOS to a fixed release: 6.49.21, 7.23.4, or 7.24.2 as applicable for your device.
- If you cannot patch immediately, block or limit SSH access to RouterOS devices from untrusted networks and restrict management plane exposure.
- Monitor device logs for unexpected logins or privilege changes and hunt for indicator activity around the SSH login helper.
- Follow vendor guidance and apply any additional mitigations recommended by MikroTik.
Frequently asked questions
Is CVE-2026-86060 being actively exploited?
CISA added CVE-2026-86060 to its Known Exploited Vulnerabilities catalog on 2026-09-10, and public exploit code is available.
Which RouterOS versions are affected by CVE-2026-86060?
RouterOS versions 6.0.0 through before 6.49.21, 7.0.0 through before 7.23.4, and 7.24 through before 7.24.2 are listed as affected.
Is there a patch for CVE-2026-86060?
Yes; fixed releases are 6.49.21, 7.23.4, and 7.24.2 for the respective branches.
Does CVE-2026-86060 require authentication?
No; the issue can be triggered without valid credentials by reaching the RouterOS SSH login helper.
References
- nvd.nist.gov/vuln/detail/CVE-2026-86060
- cve.org/CVERecord?id=CVE-2026-86060
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060
- cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited
- npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain
- mikrotik.com/supportsec/september-2026-vulnerability
- forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- All MikroTik CVEs on CVE Radar
- CVEs published in September 2026