


Perceptive Security
SOC/SIEM Consultancy

MikroTik RouterOS and Cloud Hosted Router
Published:
28 July 2026 at 12:00:00
Alert date:
28 July 2026 at 16:04:03
Source:
cisa.gov
Network Infrastructure, Critical Infrastructure, Identity & Access
CISA has published an ICS advisory regarding a high-severity vulnerability (CVE-2026-16347) affecting MikroTik RouterOS and Cloud Hosted Router (all versions). The vulnerability stems from improper restriction of excessive authentication attempts in the API authentication handling, lacking effective rate-limiting, account lockout, or source-based restrictions. Attackers on adjacent networks can bypass a fixed per-connection delay by using concurrent sessions, enabling high-volume brute-force password guessing. The CVSS v3.1 score is 8.8 (HIGH), with attack vector adjacent network, no privileges required, and high impact on confidentiality, integrity, and availability. No patch is currently available from MikroTik. Mitigations include using VPNs, restricting API access to trusted networks, applying firewall rules, and using strong randomly generated passwords. The vulnerability was reported by Andre Santos of União Geek. No known public exploitation has been reported at this time, and the vulnerability is not remotely exploitable.
Technical details
Mitigation steps:
Affected products:
MikroTik RouterOS
MikroTik Cloud Hosted Router
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-05.json
https://www.cve.org/CVERecord?id=CVE-2026-16347
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
https://mikrotik.com/support
https://cwe.mitre.org/data/definitions/307.html
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
