CRITICAL
9.8 CVE-2026-63586 Published 25 Aug 2026
RouterOS uhttpd CGI Shell Injection
Worried this affects one of your servers?
The web-based management interface of RouterOS uses a modified uhttpd server with CGI shell scripts.
An unauthenticated attacker with network access can exploit a lack of sanitization in the HTTP Basic Authentication username to execute arbitrary commands with root privileges.
Reference: CVE-2026-63586 on NVD
← Back to Security News