CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities to its KEV catalog, impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Attackers are chaining these flaws to gain administrative control of vulnerable systems, deploying backdoors and malicious plugins. Patching is required by specific deadlines to mitigate the risk of unauthorized access and system compromise.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, targeting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities are currently being actively exploited in the wild.
Specifically, CISA has added the following:
- CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's scope.
- CVE-2026-42018 (CVSS score: 7.5) - An improper authentication vulnerability in JFrog Artifactory that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially leaking sensitive resources.
- CVE-2026-84869 (CVSS score: 9.9) - An improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect that could allow an attacker to file transfer and execute through an active remote session without authorization or host confirmation.
- CVE-2026-67277 (CVSS score: 8.8) - A missing authentication for a critical function vulnerability in MikroTik RouterOS that could allow kernel memory disclosure and denial-of-service in the btest service.
- CVE-2026-86060 (CVSS score: 9.2) - An improper neutralization of argument delimiters in a command vulnerability in MikroTik RouterOS that could allow an attacker to change the trusted RouterOS policy mask and achieve privilege escalation.
As previously reported by The Hacker News, attackers have been observed chaining CVE-2026-82329 (CVSS score: 9.8) alongside the Artifactory bugs to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026. Huntress has linked the exploitation of CVE-2026-84869 to a set of three unrelated incidents where threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. ConnectWise has described the flaw as a "condition" in the ScreenConnect client that "may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances."
CERT Polska reported last week observing unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication, a campaign dubbed MikroTrick. Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
