CVE-2026-86060
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for t
CVSS
—
No CVSS
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Published: Sep 5, 2026 · Last modified: Sep 8, 2026 · CWE-88
0.4%EPSS · 30 days0.4%
2026-09-062026-09-07
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
- cert.plhttps://cert.pl/en/posts/2026/09/mikrotik-routeros-cve
- cert.plhttps://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- forum.mikrotik.comhttps://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802
- forum.mikrotik.comhttps://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801
- forum.mikrotik.comhttps://forum.mikrotik.com/t/7-24-2-stable-is-released/272800
- mikrotik.comhttps://mikrotik.com/supportsec/september-2026-vulnerability/
- npratley.nethttps://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-713779.8 CRI—
——0Command Argument Injection Vulnerability in Cosminexus Component Container.
This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 through 11-00-12, from 09-87 before 09-87-10, from 09-80 through 09-80-04, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.9hCVE-2026-84256—31.5%
——9An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject4hCVE-2026-856267.5 HIG18.9%
——6git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.6hCVE-2026-742376.5 MED14.0%
——4GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary iperf flags. An authenticated attacker with Unprivileged (lowest-level) access can supply the iperf -F flag to read an arbitrary file from the system and transmit its contents to an attacker-controlled server.4dCVE-2026-796856.5 MED12.3%
——4Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.7dCVE-2026-55673—35.7%
——11PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without sufficient escaping. Attacker-controlled values reaching UnixLocalCommandExecutor.execute, WindowsLocalCommandExecutor.execute, LocalComputationManager.execute, ParallelLoadFlowActionSimulator.run, ActionSimulatorTool.run, AmplModelRunner.run, or AmplModelRunner.runAsync can break out of the intended command and execute arbitrary shell commands as the JVM user. The affected itools paths include action-simulator with task-count, security-analysis with external, and dynamic-security-analysis. Downstream CLI tools, libraries, REST front ends, and multi-tenant grid-analysis services that forward less-trusted contingency identifiers or computation parameters into these APIs can expose the injection remotely. This issue is fixed in version 7.2.2.8d