CVE CVE-2026-16347
Severity HIGH · CVSS 3.1 8.8 · CVSS 4.0 8.7
Weakness CWE-307
Affected versions All versions
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-07-28

What is the CVE-2026-16347 vulnerability?

The vulnerability consists of insufficient restriction of excessive authentication attempts (CWE-307) in the handling of RouterOS API authentication. The system does not apply significant rate-limiting, account locking, or source-based restrictions, allowing an attacker to continue sending failed authentication requests without triggering a defensive response. In some versions, a fixed delay per connection is present, but this can be bypassed by using concurrent sessions, thereby maintaining a high volume of attempts.

Which RouterOS versions are vulnerable?

All RouterOS versions are vulnerable to CVE-2026-16347. A stable fixed version that resolves the issue has not yet been announced.

Is my router at risk?

A router is exposed if the RouterOS API is active and reachable from untrusted networks. The API is a service used by scripts and management software; if no program uses it, the risk is eliminated by disabling it. If the API is required for management, the router is at risk if it is not restricted to the specific hosts that call it, allowing external attackers to attempt authentication.

Is the CVE-2026-16347 vulnerability actively exploited?

As of the date of this article, there is no evidence that the vulnerability is being actively exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as subject to known exploitation.

How to protect the router from CVE-2026-16347?

The primary protection consists of managing access to the API. If the API is not used by scripts or management software, it should be disabled. If it is necessary, access must be restricted exclusively to authorized management hosts, preventing reachability from untrusted networks. Pending a fixed version, these measures drastically reduce the attack surface for massive authentication attempts.

Which RouterOS commands are needed to mitigate CVE-2026-16347?

Temporary mitigation: api service

The defect concerns the RouterOS API, used by scripts and management software. If no program uses it, it should be turned off; otherwise, it should be restricted to the hosts that call it.

/ip service print
# se l'API non serve
/ip service set api disabled=yes
/ip service set api-ssl disabled=yes
# se serve: solo dagli host che la usano (sostituisci con i tuoi)
/ip service set api-ssl address=192.168.88.10/32

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2026-16347?

CVE-2026-16347 has a CVSS v3.1 score of 8.8, classified as HIGH severity, with vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Is authentication required to exploit CVE-2026-16347?

No, authentication is not required to attempt exploitation of CVE-2026-16347; the vulnerability specifically concerns the ability to make repeated failed authentication attempts without restrictions.

What is the technical weakness (CWE) associated with CVE-2026-16347?

The technical weakness associated with CVE-2026-16347 is CWE-307, defined as “Improper Restriction of Excessive Authentication Attempts”.

Is a version of RouterOS available that fixes CVE-2026-16347?

No fixed version for CVE-2026-16347 has been announced yet; all current versions are vulnerable.

Official sources