MikroTik RouterOS and Cloud Hosted Router were disclosed with CVE-2026-16347, a high-severity authentication weakness that allows excessive login attempts because the API lacks effective brute-force protections. The advisory says fixed per-connection delays can be bypassed through concurrent sessions, leaving administrative interfaces exposed to credential guessing across affected versions. Recommended mitigations include applying vendor updates, enforcing stronger rate limiting and account lockout, and restricting access by source IP.
A separate disclosure from SBA Research said DFIR-IRIS 2.4.26, and possibly other versions, also lacks meaningful brute-force defenses on both password authentication and MFA OTP validation, tracked as CVE-2026-16971 and CVE-2026-18362. Researchers reported no observable rate limiting, delay, or lockout on either endpoint, allowing rapid submission of the full 6-digit OTP space and undermining MFA protections; no vendor fix was available at disclosure. The flaws align with established guidance from CWE-770 and OWASP API Security on unrestricted resource use and missing throttling, which recommend hard limits, quotas, and rate controls to prevent abuse.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
SBA Research publicly disclosed CVE-2026-16971 and CVE-2026-18362 affecting DFIR-IRIS 2.4.26 and possibly other versions, stating that MFA OTP validation and password authentication lacked observable rate limiting, delay, or account lockout. The advisory said no vendor fix was available at the time of disclosure.
CVE-2026-16347 was published for MikroTik RouterOS and Cloud Hosted Router, describing excessive authentication attempts caused by ineffective brute-force protections in the API. The advisory says all versions are affected.
A high-severity denial-of-service flaw, CVE-2026-59248, was published for Ninenines cowlib, where unbounded HPACK/QPACK prefixed-integer decoding can trigger large Erlang bignum allocations and exhaust memory. The advisory says versions from 2.0.0 before 2.19.0 are affected and upgrading to 2.19.0 or later fixes the issue.
Zellic published research detailing how weak PRNG usage in the Dart/Flutter ecosystem enabled practical attacks against the Dart SDK's tooling daemon, Proton Wallet, and SelfPrivacy.
After the 2024 responsible disclosure, Google, Proton, and SelfPrivacy issued fixes for vulnerabilities caused by insecure use of Dart's non-cryptographic Random() API.
Zellic states that weaknesses affecting the Dart SDK, Proton Wallet, and SelfPrivacy were responsibly disclosed in 2024 before vendors issued fixes.
OWASP's API Security Top 10 2023 documents API4:2023, Unrestricted Resource Consumption, as a recognized API security risk category.
MITRE CWE documents CWE-770, Allocation of Resources Without Limits or Throttling, describing a weakness that can enable denial of service through resource exhaustion and outlining mitigations and examples.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcezellic.io
Open sourceowasp.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.