Security Alert
MikroTik RouterOS Under Active Attack (CVE-2026-86060): When There's No CVSS Score to Wait For
MikroTik RouterOS is being actively exploited, and CVE-2026-86060 is in the CISA KEV catalog. Here is the interesting part for anyone who prioritizes by severity score: at the time of writing, this CVE has no CVSS score. NVD has not analyzed it yet. If your triage process starts with "what's the CVSS," this one falls through the cracks while attackers are already using it. That gap is exactly what SSVC is built to close. What the vulnerability is CVE-2026-86060 is a privilege escalation flaw