🔐 CVE Alert

CVE-2026-16347

HIGH 8.8

Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.

CWE CWE-307
Vendor mikrotik
Product routeros
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new high vulnerabilities affecting mikrotik routeros are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

MikroTik / RouterOS
All versions
MikroTik / Cloud Hosted Router
All versions

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05

Credits

Andre Santos of União Geek reported this vulnerability to CISA.