VulnOps
2026-09-11Two critical MikroTik RouterOS vulnerabilities (CVE-2026-86060 and CVE-2026-67277) expose command injection and authentication bypass flaws in widely-deployed infrastructure equipment. These vulnerabilities present immediate privilege escalation and kernel-level security risks that require urgent assessment across network environments.
- →CVE-2026-86060: MikroTik RouterOS Command Injection Privilege Escalation: Practitioners must identify RouterOS instances in their environments and assess exposure to this command injection vector that enables privilege escalation on critical network infrastructure.
- →CVE-2026-67277: MikroTik RouterOS Authentication Bypass for Critical Functions: This authentication bypass directly impacts kernel security and availability, requiring immediate verification that deployed RouterOS versions are patched to prevent unauthorized access to critical functions.
- →Dual MikroTik Vulnerabilities in Widely-Deployed Equipment: The convergence of two critical flaws in the same widely-used platform creates compounded risk requiring prioritized remediation and network segmentation review.
Immediately inventory MikroTik RouterOS deployments, check patch status against CVE-2026-86060 and CVE-2026-67277, and prioritize remediation for any unpatched instances given the critical nature of both vulnerabilities.
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.