๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Summary
MikroTik RouterOS has a vulnerability where attackers can improperly use argument delimiters (special characters that separate commands) to bypass security controls and gain higher privileges on the system. This vulnerability is currently being exploited by real attackers in the wild.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-09-13.
Vulnerability Details
EPSS: 0.4%
Yes
๐ฅ Actively Exploited
September 9, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86060
First tracked: September 10, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%