Vulnerabilities
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and MikroTik RouterOS Flaws to KEV
Cyber RTSeptember 15, 20263 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog due to active exploitation. These flaws enable privilege escalation, unauthorized access, and control over systems. Attackers have been chaining these vulnerabilities for administrative control and deploying backdoors. CISA mandates federal agencies to patch these flaws by specified September 2026 deadlines.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include five new security flaws. These vulnerabilities affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, following reports of their active exploitation. This move underscores the ongoing threat posed by these vulnerabilities and the need for organizations to address them promptly.
The vulnerabilities in JFrog Artifactory include CVE-2026-42016, which has a CVSS score of 8.1 and involves incorrect authorization that could lead to privilege escalation. Another flaw, CVE-2026-42018, with a CVSS score of 7.5, is due to improper authentication that could leak sensitive resources by returning an internal anonymous-user token to an unauthenticated caller. Both vulnerabilities highlight significant security risks that could be exploited by attackers to gain unauthorized access.
ConnectWise ScreenConnect is affected by CVE-2026-84869, a vulnerability with a CVSS score of 9.9. This flaw involves improper privilege management and missing authorization, allowing attackers to transfer files and execute them through an active remote session without authorization. This vulnerability has been exploited in several incidents, demonstrating its potential for significant harm if left unaddressed.
MikroTik RouterOS has two critical vulnerabilities: CVE-2026-67277 and CVE-2026-86060. The former, with a CVSS score of 8.8, involves missing authentication for a critical function, potentially leading to kernel memory disclosure and denial-of-service. The latter, with a CVSS score of 9.2, involves improper neutralization of argument delimiters in a command, allowing attackers to change the trusted RouterOS policy mask and escalate privileges.
Attackers have been observed chaining the two Artifactory vulnerabilities with CVE-2026-82329 to gain administrator control of self-hosted servers. This exploit chain has been used to deploy backdoors and create persistent administrator accounts, highlighting the sophisticated nature of these attacks. The exploitation of these vulnerabilities underscores the importance of timely patching and robust security measures.
The exploitation of the ScreenConnect vulnerability has been linked to incidents where threat actors used it to distribute malicious VBScript payloads. ConnectWise has acknowledged the flaw and described it as a condition that may allow unauthorized file transfers and execution. Organizations are urged to update to the latest version to mitigate this risk.
CISA's addition of the MikroTik RouterOS vulnerabilities follows reports of their exploitation by unknown threat actors. The cybersecurity agency has set deadlines for federal agencies to patch these vulnerabilities, emphasizing the urgency of addressing these security flaws. This proactive approach aims to mitigate the risk of exploitation and protect critical infrastructure.
In conclusion, the inclusion of these vulnerabilities in CISA's KEV catalog highlights the ongoing threat posed by cyberattacks exploiting these flaws. Organizations are encouraged to follow CISA's guidance and implement necessary patches to safeguard their systems. Staying informed and proactive in addressing security vulnerabilities is crucial in the ever-evolving landscape of cybersecurity threats.


