← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 11, 2026 · 12:06via CyberPress

CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges

Brief

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in the wild.

Tracked as CVE-2026-86060 , the issue affects MikroTik RouterOS and stems from improper neutralization of argument delimiters in a command, a weakness categorized as CWE-88.

Successful exploitation lets an attacker alter the trusted RouterOS policy mask, potentially elevating privileges beyond their intended authorization level.

CISA Warns MikroTik RouterOS Flaw

RouterOS policy masks are used to define access controls and determine which administrative functions a user or process can execute on a MikroTik device.

Read more on CyberPress→