CISA

MikroTik RouterOS and Cloud Hosted Router

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.

The following versions of MikroTik RouterOS and Cloud Hosted Router are affected:

RouterOS vers:all/* (CVE-2026-16347)

Cloud Hosted Router vers:all/* (CVE-2026-16347)

Vendor

Equipment

MikroTik

MikroTik RouterOS and Cloud Hosted Router

Improper Restriction of Excessive Authentication Attempts

Critical Infrastructure Sectors: Information Technology, Commercial Facilities

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Latvia

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defens...