What is CVE-2026-86060?
CVE-2026-86060 is a vulnerability classified as Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), affecting RouterOS (affected versions: 7.24 – < 7.24.2, 7.0.0 – < 7.23.4, and other affected versions). This vulnerability is rated Critical, with a CVSS score of 9.2. This vulnerability has been observed being exploited in the wild.
