Cybersecurity
Network Infrastructure
Vulnerability Management

Critical Vulnerability Chain in MikroTik RouterOS Exposes Global Network Infrastructure

September 29, 2026
1 min read
Source
Critical Vulnerability Chain in MikroTik RouterOS Exposes Global Network Infrastructure

What Happened?

Threat actors are actively exploiting a sophisticated chain of two vulnerabilities in MikroTik routers to hijack devices. The attack utilizes CVE-2026-86060, an argument-handling flaw within the SSH login sequence, to manipulate the device's RouterOS policy mask.

By leveraging specific usernames starting with prohibited characters, attackers can escalate privileges without authentication. CISA has formally acknowledged the risk, highlighting how the improper enforcement of behavioral workflows allows unauthenticated actors to seize control of exposed hardware.

Why It Matters

MikroTik routers are ubiquitous in both small office/home office (SOHO) and enterprise environments. Because these devices act as the primary gateway for network traffic, a successful compromise provides attackers with a persistent foothold, allowing for traffic interception, credential harvesting, and the potential lateral movement into internal corporate segments.

Key Details & Takeaways

  • Exploitation of CVE-2026-86060 allows for full privilege escalation via SSH login path manipulation.
  • Attackers require only an internet-exposed SSH service to trigger the unauthenticated command execution.
  • CISA has identified the flaw as a critical risk due to the chaining of improper behavioral workflow enforcement.