Our takeCISA published ICSA-26-209-05 on MikroTik RouterOS and Cloud Hosted Router: weak password hashing (CVE-2026-16347) that lets attackers brute-force credentials quickly. Patch or rotate credentials on every device you manage.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_ics · cisa_ics
What this means for you — Security leader:If MikroTik RouterOS or Cloud Hosted Router is in your estate, treat CVE-2026-16347 as a confirmed password-guessing path to unauthorized access on all versions. Inventory instances (especially any with exposed management), enforce strong unique credentials and management-plane restrictions, and apply the vendor fix when available.
What this means for you — Lean IT orgs:If you run a MikroTik router for the office or remote sites, change weak or shared admin passwords now and turn off management access from the internet. Ask your IT provider or vendor for a patched RouterOS/CHR build and install it when ready.
What this means for you — MSP:Inventory client sites on MikroTik RouterOS or Cloud Hosted Router; prioritize WAN-exposed management and weak credentials. Push credential hardening, management-plane lockdown, and the vendor patch across affected customer stacks.
What this means for you — Researcher:CISA ICSA-26-209-05 confirms CVE-2026-16347 on all RouterOS and Cloud Hosted Router versions: rapid password guessing to unauthorized system access. Track MikroTik’s CSAF/advisory for fix versions, auth surface, and preconditions.