MikroTik RouterOS SSH Login Privilege Escalation and Unauthenticated Bandwidth-Test Service Vulnerabilities

Release Date: 10th September 2026

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, Internet Service Providers, and System/Network administrators that operate a MikroTik router or other device running RouterOS. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-86060 and CVE-2026-67277 are two vulnerabilities in MikroTik RouterOS, the operating system used across MikroTik's widely-deployed router and wireless networking hardware. CVE-2026-86060 is a flaw in the SSH login path: a username beginning with prohibited characters allows an attacker with an unauthenticated SSH session to manipulate RouterOS's trusted policy mask and escalate privileges. CVE-2026-67277 is unrelated in mechanism: RouterOS accepts unauthenticated "related" bandwidth-test (btest) connections before primary session authentication completes, allowing an attacker to trigger an integer underflow that discloses kernel memory and can crash and restart the device.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-86060
  2. https://www.cve.org/CVERecord?id=CVE-2026-67277
  3. https://mikrotik.com/supportsec/september-2026-vulnerability/