The Exploit Bulletin — Monday, September 7, 2026: 2 issues require action
Monday, September 7, 2026 — 2 issues require action. If you run none of the software below, you are done.
Affects: N-able N-central · MikroTik RouterOS
1. Pre-authentication remote code execution in N-able N-central RMM (CVE-2026-86218)
REMOTE CODE EXECUTION · CRITICAL · CVSS 10.0
VulnCheck added this pre-auth RCE to its known-exploited catalog on 2026-09-06 citing N-able's own status event, and an unpatched N-central server is a single hop to every endpoint it manages.
N-central servers before 2026.3.1.14 allow an unauthenticated remote attacker to execute code on the server. Because N-central is a remote monitoring and management platform, compromise of the server exposes every managed endpoint to follow-on actions.
Affected: N-able N-central < 2026.3.1.14
How to Test: Check the installed N-central version in the server administration console; any build below 2026.3.1.14 is vulnerable. Review web-server access logs for unexpected requests to the N-central web interface from unknown IPs, and audit N-central for administrator accounts, scripts, or automation policies you do not recognise.
How to Patch: Upgrade N-central to 2026.3.1.14 or later. Until upgraded, restrict access to the N-central web interface to trusted networks or a VPN, and after upgrading review the server and managed devices for unexpected accounts, scheduled tasks, or scripts.
Evidence: VulnCheck KEV
2. Unauthenticated SSH login-path flaw changes RouterOS policy mask for full device takeover in MikroTik RouterOS (CVE-2026-86060)
PRIVILEGE ESCALATION · CRITICAL · CVSS 9.2
CERT Polska and Italy's CSIRT both reported active exploitation of the MikroTrick RouterOS flaws within the last two days, and a router with SSH reachable from untrusted networks and still on an unfixed release can be taken over without credentials.
An argument-handling flaw in the RouterOS SSH login helper, triggered by usernames beginning with a prohibited character, lets an attacker with only an unauthenticated SSH session alter the trusted RouterOS policy mask and escalate to full control of the router. It is one of three related flaws (with CVE-2026-67276 and CVE-2026-67277) that MikroTik groups under the codename MikroTrick.
Affected: MikroTik RouterOS >= 7.24 < 7.24.2; MikroTik RouterOS >= 7.0.0 < 7.23.4; MikroTik RouterOS >= 6.0.0 < 6.49.21
How to Test: Check the running RouterOS version under System/Packages; anything below 6.49.21 (v6), 7.23.4 (7.x long-term) or 7.24.2 (7.24 stable) is vulnerable. Check whether SSH is reachable from untrusted networks. Inspect the Log section for a critical entry stating the device has been Flagged, and review the configuration for unknown scripts, users, or other settings you do not recognise.
How to Patch: Upgrade via System/Packages > Check For Updates to 6.49.21 (long-term v6), 7.23.4 (long-term v7), 7.24.2 (stable) or 7.25 beta 3; MikroTik notes the v6 branch is no longer actively developed and recommends moving to v7. Make a backup/export first. Independently, ensure SSH is not open to untrusted networks, restrict it to trusted IPs, or reach the router only over a VPN such as WireGuard. If the device shows Flagged status, follow MikroTik's Flagged status documentation; after upgrading, remove any unknown scripts, users, or configuration.
Evidence: VulnCheck KEV · CERT Polska: critical RouterOS vulnerabilities actively exploited, immediate update recommended · ACN / CSIRT Italia alert AL01/260906: exploitation of new MikroTik vulnerabilities observed in the wild · Reverse engineering of the RouterOS 7.23.4 silent patch
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].