Junglewise Threat Intelligence

CVE-2026-86060: MikroTik RouterOS argument delimiter neutralization privilege escalation

CVE-2026-86060 · Severity: critical · Exploited in the wild · Published 2026-09-10

Executive brief

MikroTik RouterOS is a widely deployed network operating system used to manage routers and network appliances. This vulnerability allows an attacker to manipulate security policy masks through improper command argument handling, enabling them to escalate privileges and gain unauthorized administrative control over affected devices. Exploitation has been observed in the wild, posing an immediate threat to network infrastructure security.

Technical details

This vulnerability is a command argument delimiter injection issue in MikroTik RouterOS where insufficient sanitization of command-line arguments permits an attacker to bypass security controls. The flaw resides in the command processing mechanism that handles policy mask configuration. An attacker can craft malicious commands with specially crafted delimiters to alter the trusted policy mask, effectively circumventing access controls and escalating privileges. The vulnerability is exploitable by authenticated or network-adjacent users depending on the RouterOS configuration exposed. Patches or firmware updates from MikroTik are likely available; administrators should verify the latest security advisories.

Affected products

  • MikroTik RouterOS

Timeline

  • 2026-09-10: disclosed
  • exploited: Reported exploited in the wild

Related threats