MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.
Quick answers
What is CVE-2026-86060?
MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.
How severe is CVE-2026-86060?
critical, CVSS 9.8
Is CVE-2026-86060 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-86060 be mitigated?
MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.
CVSS
9.8
Vendor
MikroTik
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
MikroTik RouterOS
Mitigation
MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.
Security researchers from CERT Polska have disclosed a chained vulnerability affecting MikroTik RouterOS SSH implementation. The exploit combines CVE-2026-67279, an SSH state-machine flaw, with CVE-2026-86060, an argument-injection bug in the login process. Successful chaining of these vulnerabilities allows attackers to gain full administrative control of Internet-exposed MikroTik routers without requiring a password, SSH key, or completing authentication. MikroTik has addressed the flaws in RouterOS version 7.0.4 and later.