HIGHVulnerability
Verified
Global

CISA KEV: MikroTik RouterOS — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

Analysis

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-10. Remediation due: 2026-09-13.

Indicators of Compromise (1)

CVE (1)
CVE-2026-86060
Source Attribution

Originally published by CISA KEV on Sep 10, 2026. Verified by: CISA.

Related Threats