Skip to content
VulniPulse
Critical9.2MikroTik

Critical [CVE-2026-86060] SSH session privilege manipulation via a crafted username in Mikrotik RouterOS

This critical-severity MikroTik advisory covers CVE-2026-86060 affecting MikroTik RouterOS.

CVE-2026-86060 Published Sep 5, 2026Updated by vendor Sep 5, 2026
Affected products & platforms
MikroTikRouterOS
Open vendor advisory

Android app · Google Play

Monitor future MikroTik CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels. This is an important security update.

Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.

Your device should already give you the option to upgrade software in the “Check for updates” menu. Fix is included in: 7.25 beta 3.

7.24.2. 7.23.4.

6.49.21. For regular home device users the issue does not pose an immediate risk, but we still suggest all users to upgrade.

Steps to be taken Make sure SSH is not open to any untrusted networks. MikroTik default configuration blocks this port from the internet by default, but if you have manually opened this port, make sure only trusted IP can access it, or better yet, use a strong VPN like WireGuard to access your router and do not open any management ports at all.

RouterOS will check if your device has been compromised, and set it to “Flagged” status if it is. This will be written in the “Log” section.

Affected product named by the advisory: MikroTik RouterOS.

Affected versions
  • RouterOS 7.24 before 7.24.2
  • RouterOS 7.0.0 before 7.23.4
  • RouterOS 6.0.0 before 6.49.21

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Fixed versions
  • 7.24.2
  • 7.23.4
  • 6.49.21

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Mitigation

Upgrade to a fixed release: 7.24.2, 7.23.4, 6.49.21. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 1 hour ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.