CISA added two distinct MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 10, 2026, confirming active exploitation of both: CVE-2026-86060 (CVSS 3.1 base 9.8, critical) and CVE-2026-67277 (CVSS 3.1 base 8.2, high). Both were fixed by MikroTik in the same set of releases: 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
CVE-2026-86060: SSH login argument injection
Classified under CWE-88 (Improper Neutralization of Argument Delimiters in a Command), this flaw is an argument-handling bug in RouterOS’s SSH login path. Per NVD’s description, a username beginning with a prohibited character can alter the trusted RouterOS policy mask, leading to privilege escalation. Exploitation requires only an unauthenticated SSH session reaching the RouterOS login helper — no valid credentials needed. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects full confidentiality, integrity, and availability impact from a network-reachable, low-complexity attack.
CVE-2026-67277: unauthenticated bandwidth-test crash
Classified under CWE-306 (Missing Authentication for Critical Function), this flaw involves RouterOS’s “btest” (bandwidth test) feature. NVD’s description explains that RouterOS accepts a “related” btest connection before the corresponding primary session finishes authenticating. An unauthenticated client can use this state to start an IPv4 UDP test; with random-data=false, the sender transmits an uninitialized tail from a kernel packet buffer, and a separate unchecked, inverted packet-size interval causes unsigned integer underflow — producing anomalously large fragmented output that can restart the RouterOS kernel. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) reflects primarily an availability impact (a crash/restart condition) rather than the full-compromise profile of CVE-2026-86060.
Why they’re on KEV together
CISA added both CVEs to the KEV catalog on the same date, September 10, 2026, indicating both have confirmed real-world exploitation. Under Binding Operational Directive (BOD) 26-04, affected organizations are directed to apply vendor mitigations and independently assess each device’s internet exposure, rather than a fixed CISA-set patch deadline.
What we don’t yet have
Both records currently rest on a single source per field (NVD for CVSS/description/references, CISA KEV for title/vendor/product/mitigation metadata) — no second source has independently corroborated either record yet, so confidence is medium, not high, for both CVEs. Neither has an EPSS score or an exploit-availability classification (proof-of-concept vs. weaponized vs. observed-in-the-wild) in our data beyond the KEV listing itself.
Why this matters
RouterOS runs on a very large installed base of edge routers, many internet-facing by design. CVE-2026-86060’s privilege-escalation path via SSH login is the more severe of the two — a successful exploit gives an unauthenticated attacker elevated control over the device’s own trusted policy configuration. CVE-2026-67277’s kernel-crash path is lower-severity by CVSS but still meaningfully disruptive: an unauthenticated remote actor can trigger a router restart with no credentials at all. Administrators running RouterOS versions predating the fixed releases (6.49.21, 7.23.4, or 7.24.2) should treat both as immediate patching priorities, particularly on devices with SSH or bandwidth-test functionality reachable from the internet.
Frequently Asked Questions
What is CVE-2026-86060? A CVSS 9.8 critical argument-injection flaw in MikroTik RouterOS’s SSH login path that can allow privilege escalation via a specially-crafted username, requiring no valid credentials.
What is CVE-2026-67277? A CVSS 8.2 high missing-authentication flaw in RouterOS’s bandwidth-test (btest) feature that lets an unauthenticated client trigger a kernel crash and device restart.
Are these vulnerabilities being actively exploited? Yes. CISA added both to the Known Exploited Vulnerabilities catalog on September 10, 2026, which CISA only does when it has evidence of active exploitation.
What should RouterOS administrators do? Upgrade to 6.49.21 (Long-term), 7.23.4 (Long-term), or 7.24.2 (Stable) or later — all three releases fix both vulnerabilities.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 12, 2026. See more vulnerability research.