CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
Brief
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in the wild.
Tracked as CVE-2026-86060 , the issue affects MikroTik RouterOS and stems from improper neutralization of argument delimiters in a command, a weakness categorized as CWE-88.
Successful exploitation lets an attacker alter the trusted RouterOS policy mask, potentially elevating privileges beyond their intended authorization level.
CISA Warns MikroTik RouterOS Flaw
RouterOS policy masks are used to define access controls and determine which administrative functions a user or process can execute on a MikroTik device.
