CISA listed two MikroTik RouterOS flaws on September 10, 2026. CERT Polska's vulnerable range covers every 6.x build below 6.49.21, and 6.49.21 is the…
What the two catalog entries are, and what they are not
| CVE | What it is | CVSS | Vulnerable range (CERT Polska) | On CISA KEV |
|---|---|---|---|---|
| CVE-2026-86060 | SSH session privilege manipulation via a crafted username; the session ends up with full administrative rights | 9.2 | 6.0.0 to 6.49.20; 7.0.0 to 7.23.3; 7.24 to 7.24.1 | Yes, September 10 |
| CVE-2026-67277 | Bandwidth-test service accepts an unauthenticated connection into a post-login state; leaks kernel memory or restarts the router | 8.8 | 6.0.0 to 6.49.20; 7.0.0 to 7.23.3; 7.24 to 7.24.1 | Yes, September 10 |
| CVE-2026-67276 | SSH authentication bypass: RouterOS matched an RSA key by modulus alone, so a forged key with exponent one logs in without the private key | 9.2 | 7.9 to 7.23.3; 7.24 to 7.24.1 | No, as of September 10 |
What's covered
- What the two catalog entries are, and what they are not
- Every RouterOS line against the fix list
- What to do, by line
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-mikrotik-routeros-cve-2026-86060-only-6-49-21-fixed
Top comments (0)