ZeroDayAlert

CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

MikroTik RouterOS Added to KEV 2026-09-10 Federal due 2026-09-13 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

MikroTik RouterOS is affected by an improper neutralisation of argument delimiters that permits privilege escalation through manipulation of the RouterOS policy mask. The record does not specify which versions of RouterOS are vulnerable, nor does it detail whether this affects all deployment models or only specific configurations. If your organisation operates MikroTik routers or uses RouterOS in any capacity, you should assume potential exposure pending clarification from the vendor.

How to check whether this touches you

  • Inventory all MikroTik RouterOS deployments in your environment, including version numbers and deployment context (edge routers, cloud instances, lab equipment).
  • Verify network reachability to each RouterOS instance from untrusted networks, particularly from the internet; privilege escalation is most dangerous when the attack surface is externally accessible.
  • Cross-reference your running versions against MikroTik's advisory to determine which instances require patching; note that version numbers alone do not prove whether a backported fix is present.
  • Check your access control model: identify accounts and processes with policy modification rights, as these are the likely escalation targets.
  • Review authentication logs for any unusual policy changes or administrative access outside normal change windows.

What to do

  1. Request and review the vendor's official advisory, patch availability, and remediation timeline from MikroTik immediately.
  2. If you cannot patch immediately, restrict network access to affected RouterOS instances by applying firewall rules to limit inbound connections to trusted administrative IP ranges only.
  3. Isolate any RouterOS instance that is directly internet-facing and cannot be patched within your organisation's risk tolerance; evaluate whether it can be temporarily taken offline or moved behind a jump host.
  4. Enable and centralise audit logging for policy and administrative changes on all RouterOS instances; ensure logs are retained for at least 90 days and cannot be modified by local users.
  5. Schedule patching in accordance with CISA BOD 26-04 guidance and your organisation's change control process; coordinate with network operations to minimise service disruption.
  6. Escalate to your security leadership if any RouterOS instance is internet-facing and cannot be patched or decommissioned within the federal remediation due date of 2026-09-13.

If you find you were exposed

Exploitation of privilege escalation typically occurs after an attacker has already gained a foothold on the network or an initial authentication method. Review access logs from at least 90 days before discovery to identify unexpected administrative sessions, policy modifications, or unusual command execution. Cross-reference timeline findings with any broader incident indicators—such as unexpected outbound traffic from the router or changes to routing tables—to assess whether the compromise was used as a stepping stone to other assets. Prioritise log analysis for any period when the RouterOS instance was internet-accessible and unpatched.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-86060 is being exploited. It cannot tell you whether RouterOS is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →