CVE- 2026-16347 is a critical vulnerability in MikroTik RouterOS and Cloud Hosted Router that allows attackers to execute brute-force attacks to gain unauthorized system access. Rated with a CVSS score of 8.8, the flaw enables unlimited authentication attempts, facilitating password guessing. Affected versions include all iterations of MikroTik software, with no fix currently available.
Recommended mitigations include shielding the API behind a VPN, restricting management access, applying firewall rules, and employing strong, random passwords to mitigate the risks.