Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.
The following versions of MikroTik RouterOS and Cloud Hosted Router are affected:
RouterOS vers:all/* (CVE-2026-16347)
Cloud Hosted Router vers:all/* (CVE-2026-16347)
Vendor
Equipment
MikroTik
MikroTik RouterOS and Cloud Hosted Router
Improper Restriction of Excessive Authentication Attempts
Critical Infrastructure Sectors: Information Technology, Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Latvia
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defens...
Read the full advisory on CISA →