Two Critical RouterOS Flaws Enable Privilege Escalation on MikroTik Edge Routers
Two vulnerabilities affecting MikroTik RouterOS were published to the National Vulnerability Database on September 5, 2026. The more severe flaw, CVE-2026-86060, carries a CVSS score of 9.8 and exploits a parsing error in the SSH login path, allowing attackers to alter the device's authorization policy and escalate privileges. Because RouterOS devices typically serve as internet-boundary hardware managing routing, firewalls, and VPN termination, a successful compromise grants control over an entire network perimeter. ZoomEye data identifies over 8 million assets with a RouterOS fingerprint, though this reflects the broader installed base rather than the specific count of vulnerable, internet-exposed devices. MikroTik advises operators to upgrade to a patched release on their respective stable or long-term maintenance branch, with exact version details available through the official vendor advisory.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in