CVE-2026-16347: Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router

Published Jul 28, 2026
·
Updated

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive response. In some versions, a fixed per-connection delay is present, but it can be bypassed through concurrent sessions, resulting in continued high-volume attempts. This deficiency increases the risk that an attacker could eventually obtain valid credentials and gain unauthorized access to administrative services.

Affected Software

2 affected components
Mikrotik RouterOS
Mikrotik Cloud Hosted Router

Event History

Jul 28, 2026
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-16347?

CVE-2026-16347 has a high severity rating of 8.8.

2

How do I fix CVE-2026-16347?

To fix CVE-2026-16347, implement strong rate-limiting, account lockout mechanisms, and enhance API authentication safeguards.

3

What type of systems are affected by CVE-2026-16347?

CVE-2026-16347 affects MikroTik RouterOS and MikroTik Cloud Hosted Router.

4

What is the risk posed by CVE-2026-16347?

CVE-2026-16347 poses a risk due to insufficient protections against excessive authentication attempts, which can lead to unauthorized access.

5

Is CVE-2026-16347 exploit available?

The exploit for CVE-2026-16347 is possible due to the lack of effective safeguards against repeated authentication failures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203