CRITICAL 9.8 CVE-2026-63586 Published 25 Aug 2026

RouterOS uhttpd CGI Shell Injection

Worried this affects one of your servers?

The web-based management interface of RouterOS uses a modified uhttpd server with CGI shell scripts.

An unauthenticated attacker with network access can exploit a lack of sanitization in the HTTP Basic Authentication username to execute arbitrary commands with root privileges.

Reference: CVE-2026-63586 on NVD

← Back to Security News