CVE-2026-86060
Known exploited · CISA KEV
EPSS 1% (63rd percentile).
CISA federal remediation date Sep 13 · date passed
Vulnerabilities & Exploits
CERT Polska said MikroTik’s September 3 RouterOS patches covered two flaws, CVE-2026-67279 and CVE-2026-86060, that could be chained into full device takeover without authentication. The same disclosure says administrators were already seeing logs that looked like attacks in the wild before the details were public.
The chain starts with a crafted SSH username that changes how RouterOS passes arguments to its login program, then lets an attacker pivot into a privileged session and flip trusted policy state. In plain terms, the login path itself becomes the control plane, so a box that only exposes SSH management can still hand over routing and access functions.
For operators of MikroTik edge devices, the important point is that the blast radius is the device itself and whatever it brokers for the network. The disclosure also shows that holding back exploit details did not buy much time: patch-release day was enough for public reverse engineering, and the reports suggest exposure may already have existed before the fixes were available.
1 source · 5h ago
Known exploited · CISA KEV
EPSS 1% (63rd percentile).
CISA federal remediation date Sep 13 · date passed
EPSS 0.4% (38th percentile).
CERT Polska
MikroTrick: technical analysis, disclosure process, and the use of LLM agents
We describe the technical details of the MikroTrick chain, which combines the CVE-2026-67279 and CVE-2026-86060 vulnerabilities and, when chained, allowed full takeover of a device without authentication.
originalPart of the PlainSec briefing for 2026-09-22
Every edition of this story: MikroTik RouterOS Chain Enabled Unauthenticated Takeover