CVE-2026-86060: MikroTik RouterOS
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.
- Vendor
- MikroTik
- Product
- RouterOS
- Vulnerability
- MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Date added
- Sep 10, 2026
- CISA due date (U.S. federal agencies)
- Sep 13, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-88
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02