CVE-2026-86060: MikroTik RouterOS
MikroTik RouterOS在命令脆弱性中包含了對引數劃分器的不當中性,這使得攻擊者可以改變可信賴的 RouterOS 政策掩碼,導致特權升級。
CISA (English)
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.
- 廠商
- MikroTik
- 產品
- RouterOS
- 漏洞
- MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- 加入日期
- 2026年9月10日
- CISA 修補期限(美國聯邦機關)
- 2026年9月13日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-88
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02