Executive brief
Mikrotik RouterOS is network routing software used by enterprises to manage connectivity and traffic. This vulnerability allows unauthenticated attackers to open sessions and execute commands without valid credentials, bypassing core authentication controls. Successful exploitation could grant attackers full control over network routing, leading to traffic interception, denial of service, or network compromise.
Technical details
The vulnerability is an improper enforcement of behavioral workflow in Mikrotik RouterOS that permits unauthenticated clients to establish session channels and submit exec requests. No authentication is required; any remote attacker with network access to the device can trigger the flaw. This defect can be chained with CVE-2026-86060 to achieve unauthenticated remote code execution or command execution on the router. The vulnerability has been observed actively exploited in the wild as of September 2026.
Affected products
- Mikrotik RouterOS
Timeline
- 2026-09-25: disclosed
- exploited: Confirmed exploited in the wild