CISA has published an advisory for CVE-2026-16347, an authentication weakness affecting all versions of MikroTik RouterOS and Cloud Hosted Router. The device’s API authentication handling fails to enforce meaningful rate-limiting, account lockout, or source-based restrictions, meaning repeated failed login attempts proceed without any defensive response. Where a fixed per-connection delay exists, attackers can bypass it by opening concurrent sessions, enabling high-volume credential guessing. The flaw carries a CVSS v3 score of 8.8.
For identity and access security teams, this is a classic credential-attack enabler: without lockout or throttling, exposed MikroTik management interfaces become soft targets for brute-force and password-spraying campaigns, potentially yielding full device takeover of widely deployed network gear.
What to take away: restrict and firewall RouterOS/API management access, enforce strong unique credentials, monitor for repeated authentication failures, and apply vendor updates as they become available.