CISA has added CVE-2026-86060 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects MikroTik RouterOS and involves improper neutralisation of argument delimiters in a command, allowing an attacker to alter the trusted RouterOS policy mask and escalate privileges.
The flaw is a command-injection-style argument-handling vulnerability. Successful exploitation can change RouterOS security policy settings and lead to privilege escalation. NVD assigns it a CVSS score of 9.2, rated Critical. A patch is available, with vendor guidance published by CERT Polska.
KEV listing confirms that attackers are actively exploiting the vulnerability. The available data does not identify ransomware use. CISA requires remediation by 13 September 2026.
CISA requires organisations to apply mitigations in accordance with vendor instructions and comply with its BOD 26-04 guidance on prioritising security updates based on risk, as well as its Forensics Triage Requirements. Where mitigations are unavailable, organisations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product.
Federal Civilian Executive Branch (FCEB) agencies are directly subject to this requirement, but all organisations should review their MikroTik RouterOS exposure, including internet-facing assets.
See the linked NVD entry and CISA KEV catalogue for full details.