First published · Last updated
CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS has a command vulnerability that allows changing the trusted RouterOS policy mask and can lead to privilege escalation. The source requires stakeholders to apply vendor mitigations and follow CISA BOD 26-04 guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 4/10
- Global importance
- 4/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Exploitation can result in privilege escalation on affected RouterOS devices, requiring immediate mitigation steps.

