chiprook
← Security
SecuritySeptember 26, 2026, 16:20

CVE-2026-86060 in RouterOS: admin takeover without credentials

CERT Polska detailed CVE-2026-86060 in MikroTik RouterOS, an argument-injection flaw in the login helper that grants an unauthenticated attacker a full-policy console. The fix shipped in the September 2026 RouterOS releases, and 9,559 devices with SSH-exposed RouterOS were found online.

CVE-2026-86060 in RouterOS: admin takeover without credentials
#MikroTik#RouterOS
Read next
Security

Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers

Security

Patching Guide: Closing the CVE-2026-67276 SSH Authentication Bypass on MikroTik Routers

Security

CISA adds Microsoft SharePoint and MikroTik RouterOS flaws to KEV catalog

Security

MikroTik patches three RouterOS flaws, including SSH auth bypass