CVE-2026-86060 in RouterOS: admin takeover without credentials
CERT Polska detailed CVE-2026-86060 in MikroTik RouterOS, an argument-injection flaw in the login helper that grants an unauthenticated attacker a full-policy console. The fix shipped in the September 2026 RouterOS releases, and 9,559 devices with SSH-exposed RouterOS were found online.
- CVE-2026-86060 is an argument-injection flaw in the RouterOS login helper
- A username of -2 makes the process read attacker-supplied values
- Mask 655358 grants the RouterOS full group policy
- Fixed in the September 2026 RouterOS releases
Read next
Security