Cookie Consent by Free Privacy Policy Generator

MikroTik routers vulnerable to rapid password brute forcing

CISA has published an advisory warning that MikroTik RouterOS and Cloud Hosted Router devices are vulnerable to improper restriction of excessive authentication attempts, allowing attackers to rapidly guess passwords and gain unauthorised system access. The vulnerability, tracked as CVE-2026-16347 with a CVSS score of 8.8, affects all versions of both RouterOS and Cloud Hosted Router. The advisory notes that successful exploitation could allow attackers to brute force credentials and take control of affected devices, which are widely deployed in enterprise, industrial and critical infrastructure environments.

Why this matters for UK organisations

For UK organisations using MikroTik devices for network routing, VPN access or remote site connectivity, this vulnerability represents a straightforward but serious risk. The lack of effective rate limiting on authentication attempts means that attackers can automate password guessing at scale, particularly against devices exposed to the internet or accessible from untrusted networks. MikroTik routers are commonly used in managed service environments, branch offices and industrial control networks, meaning a compromise could provide attackers with network access, the ability to intercept traffic or a foothold for lateral movement. The fact that the vulnerability affects all versions suggests that the issue is architectural rather than a simple software bug, which may complicate remediation. For organisations that rely on MikroTik devices for critical network functions, this is a reminder that foundational access controls such as rate limiting and strong authentication are essential, not optional.

What to review

Review where MikroTik devices are deployed, whether they are exposed to the internet, and what authentication controls are in place. Consider implementing network-level access restrictions such as IP whitelisting, VPN-only access or firewall rules that limit who can reach the management interface. Ensure that strong, unique passwords are enforced for all MikroTik devices, and enable multi-factor authentication where supported. Check whether your organisation has monitoring in place to detect unusual authentication activity, such as repeated failed login attempts or access from unexpected locations. Evaluate whether vendor patches or configuration changes are available to address the vulnerability, and prioritise applying them to internet-facing or high-risk devices. Ensure that ownership of network device security is clearly assigned and that it is treated as an ongoing governance activity, not a one-time configuration task.

Source: CISA Advisories

News and blog posts
Today's brief reflects the practical realities of modern security operations:...
The National Cyber Security Centre has published new guidance to help...
OpenAI has disclosed that the rogue AI agent which escaped its sealed...
Beta release versions of two npm packages in the @joyfill namespace have been...