Skip to main content
QUIETLYTIC
Advisory

Two MikroTik RouterOS Flaws Added to CISA KEV List

CISA added two MikroTik RouterOS flaws, CVE-2026-86060 (CVSS 9.8) and CVE-2026-67277 (CVSS 8.2), to its KEV catalog Sept. 10, 2026 as actively exploited.

Two MikroTik RouterOS Flaws Added to CISA KEV List — Advisory research covering CVE-2026-86060, CVE-2026-67277
Severity
Critical
Confidence
Medium
Affected
MikroTik RouterOS
Status
Active

Full CVE Roster

All 2 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 2 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability 9.8 critical Yes
CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability 8.2 high Yes

CISA added two distinct MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 10, 2026, confirming active exploitation of both: CVE-2026-86060 (CVSS 3.1 base 9.8, critical) and CVE-2026-67277 (CVSS 3.1 base 8.2, high). Both were fixed by MikroTik in the same set of releases: 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).

CVE-2026-86060: SSH login argument injection

Classified under CWE-88 (Improper Neutralization of Argument Delimiters in a Command), this flaw is an argument-handling bug in RouterOS’s SSH login path. Per NVD’s description, a username beginning with a prohibited character can alter the trusted RouterOS policy mask, leading to privilege escalation. Exploitation requires only an unauthenticated SSH session reaching the RouterOS login helper — no valid credentials needed. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects full confidentiality, integrity, and availability impact from a network-reachable, low-complexity attack.

CVE-2026-67277: unauthenticated bandwidth-test crash

Classified under CWE-306 (Missing Authentication for Critical Function), this flaw involves RouterOS’s “btest” (bandwidth test) feature. NVD’s description explains that RouterOS accepts a “related” btest connection before the corresponding primary session finishes authenticating. An unauthenticated client can use this state to start an IPv4 UDP test; with random-data=false, the sender transmits an uninitialized tail from a kernel packet buffer, and a separate unchecked, inverted packet-size interval causes unsigned integer underflow — producing anomalously large fragmented output that can restart the RouterOS kernel. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) reflects primarily an availability impact (a crash/restart condition) rather than the full-compromise profile of CVE-2026-86060.

Why they’re on KEV together

CISA added both CVEs to the KEV catalog on the same date, September 10, 2026, indicating both have confirmed real-world exploitation. Under Binding Operational Directive (BOD) 26-04, affected organizations are directed to apply vendor mitigations and independently assess each device’s internet exposure, rather than a fixed CISA-set patch deadline.

What we don’t yet have

Both records currently rest on a single source per field (NVD for CVSS/description/references, CISA KEV for title/vendor/product/mitigation metadata) — no second source has independently corroborated either record yet, so confidence is medium, not high, for both CVEs. Neither has an EPSS score or an exploit-availability classification (proof-of-concept vs. weaponized vs. observed-in-the-wild) in our data beyond the KEV listing itself.

Why this matters

RouterOS runs on a very large installed base of edge routers, many internet-facing by design. CVE-2026-86060’s privilege-escalation path via SSH login is the more severe of the two — a successful exploit gives an unauthenticated attacker elevated control over the device’s own trusted policy configuration. CVE-2026-67277’s kernel-crash path is lower-severity by CVSS but still meaningfully disruptive: an unauthenticated remote actor can trigger a router restart with no credentials at all. Administrators running RouterOS versions predating the fixed releases (6.49.21, 7.23.4, or 7.24.2) should treat both as immediate patching priorities, particularly on devices with SSH or bandwidth-test functionality reachable from the internet.

Frequently Asked Questions

What is CVE-2026-86060? A CVSS 9.8 critical argument-injection flaw in MikroTik RouterOS’s SSH login path that can allow privilege escalation via a specially-crafted username, requiring no valid credentials.

What is CVE-2026-67277? A CVSS 8.2 high missing-authentication flaw in RouterOS’s bandwidth-test (btest) feature that lets an unauthenticated client trigger a kernel crash and device restart.

Are these vulnerabilities being actively exploited? Yes. CISA added both to the Known Exploited Vulnerabilities catalog on September 10, 2026, which CISA only does when it has evidence of active exploitation.

What should RouterOS administrators do? Upgrade to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable) or later — all three releases fix both vulnerabilities.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools