Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers
NVD published CVE-2026-86060 (CVSS 9.8) and CVE-2026-67277 (CVSS 8.2) in MikroTik RouterOS. The first allows privilege escalation via a username parsing error in SSH; the second allows running a UDP test without authentication and obtaining uninitialized data from the kernel buffer. The fix is updating firmware and closing SSH and btest from the internet.
- CVE-2026-86060: CVSS 9.8, policy mask change via SSH username
- CVE-2026-67277: CVSS 8.2, btest UDP test without authentication
- ZoomEye indexes 8,083,155 devices with RouterOS
- Measures: update, close SSH and btest, audit accounts and logs
Read next
Security