MikroTik RouterOS flaw added to US 'actively exploited' list — but details are thin on the ground
CISA says CVE-2026-86060 is being used in real attacks against MikroTik routers, yet neither the agency nor NVD has published what the bug actually does.
A vulnerability affecting MikroTik’s RouterOS software has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalogue, meaning CISA has evidence it’s being actively used in attacks, not just theorised about in a lab. The entry, tracked as CVE-2026-86060, was added on 10 September 2026, with US federal agencies given until 13 September to patch or mitigate it.
That’s the solid part. What’s less clear, at time of writing, is almost everything else.
What we actually know
CISA’s KEV listing confirms three things: the flaw is real, it’s in MikroTik RouterOS, and someone is exploiting it in the wild right now. That’s precisely the bar the KEV catalogue exists to clear — CISA only adds vulnerabilities it has confirmed evidence of active exploitation for, unlike the thousands of “theoretically dangerous” CVEs that never get touched by real attackers. Federal civilian agencies in the US are contractually obliged to patch listed flaws by the given deadline under Binding Operational Directive requirements; that’s a compliance stick for government departments, not a UK legal requirement, but it’s a solid signal that this isn’t a paper tiger.
Beyond that, the public record is oddly bare. Neither the NVD entry nor the KEV catalogue notes we’ve seen include a description of the vulnerability class — whether it’s a remote code execution bug, an authentication bypass, or something else entirely. There’s no confirmed list of affected RouterOS versions, no CVSS severity score quoted, and CISA lists the ransomware association as “Unknown” rather than confirmed. In short: we know it’s being exploited, but not precisely how, by whom, or against what specific configurations.
So who is actually at risk
RouterOS runs on MikroTik’s range of routers, switches and wireless gear — kit that’s popular with ISPs, network engineers, small businesses and a fair few enthusiast home-lab users, but not something most ordinary broadband customers will have sitting under their telly. If you’ve never heard of MikroTik, you almost certainly aren’t using it; this is enterprise and prosumer networking hardware, not a Sky or BT router.
That said, MikroTik devices have a long history of being conscripted into botnets precisely because operators sometimes leave management interfaces exposed to the internet. Given the details here are sparse, it would be premature to say exactly what “actively exploited” looks like in practice — mass internet scanning, or targeted attacks against specific networks. Until MikroTik or CISA publish more, that distinction matters for how urgently anyone should react.
What to do about it
If you administer MikroTik RouterOS gear — for a business, an ISP, or a serious home network — the sensible move is to check MikroTik’s own advisories and changelog for a patched release, and in the meantime make sure the router’s management interface (WinBox, web admin, API) isn’t exposed to the open internet. That single step closes off the most common way these devices get compromised, regardless of the specific bug involved.
For everyone else, this is a case of watching rather than panicking. The takeaway: a real, confirmed-exploited flaw exists in a widely used piece of networking kit, but the public detail needed to judge its true severity hasn’t caught up yet. Worth a note to your IT team if you run MikroTik hardware — not a reason for the average reader to lose sleep.