CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations.
#MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity
https://securityonline.info/mikrotik-routeros-cve-2026-16347
TL;DR
CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
- CVE: CVE-2026-16347
- CVSS: 8.8 (High · CVSSv3)
- Product: MikroTik RouterOS
- Affected: All versions
- Impact: Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router
- Status: No confirmed exploitation yet
- EPSS: 0.2% (30-day)
- Action: See vendor advisory
Why it matters
MikroTik gear sits at the edge of countless networks worldwide. It runs on hardware routers and virtual cloud instances alike. Therefore a router takeover can expose everything behind it. An attacker who cracks a login can rewrite firewall rules, redirect traffic, or plant backdoor accounts. From there, they can pivot deeper into the network.
How the attack works
The weakness lives in the API authentication handling. According to CISA, the system “does not enforce meaningful rate-limiting, account lockout, or source-based restrictions.” So repeated login failures continue without pushback. Some versions add a small per-connection delay, but concurrent sessions bypass it. As a result, an attacker can run high-volume password guessing. This is not a bypass, since valid credentials are still needed.
Affected versions
The flaw affects all versions of MikroTik RouterOS and Cloud Hosted Router. That includes both hardware routers and cloud instances. CISA lists the products as deployed worldwide. No public exploitation or proof-of-concept has been confirmed.
Patch and mitigation
No fix exists yet, so mitigation is essential. MikroTik and CISA outline several steps in the CISA advisory. Shield the API behind a VPN, and restrict management access to trusted networks. Apply firewall rules, and use long, random passwords. These steps keep the brute-force search space impractically large for the MikroTik RouterOS API.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.