LIVE · cybersecurity feed
Live wire
cve recordzero day2 of 3 cataloguesexploit reported

CVE-2026-86060

CVSS
Severitynone
Weakness
EPSS0.40%33.4th percentile
Exploited2 KEV sources
patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 2 KEV catalogues that list it.

The life of this vulnerability

  1. CVE published
  2. First KEV listingsame day
  3. Last sightingsame day

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources2 of 3
Listings differ by0 d
Strongest claimconfirmed

2 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

4 public reports collected from VulnCheck and CIRCL, first on Sep 5, 2026. Each links to its original source. We have not verified them.

Description

References

← Back to the CVE Tracker

Our coverage of CVE-2026-86060

CVE-2026-67276critical

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

MikroTik routers are actively being exploited through a vulnerability chain dubbed "MikroTrick," which combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060). This allows attackers to gain full administrator control over internet-exposed devices with SSH enabled. Exploitation began as early as September 2nd, prior to the release of patches. Users are urged to update to the latest stable versions and check logs for indicators of compromise, such as failed SSH logins with the username "-2" or the creation of an "ops" user account.