Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-42016 and CVE-2026-42018 Vulnerabilities

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog.

The additions follow reports of exploitation in the wild, including attacks that used the Artifactory flaws to gain administrative access and RouterOS vulnerabilities to take control of network devices.

Five Vulnerabilities Added

CVE Product CVSS Impact
CVE-2026-42016 JFrog Artifactory 8.1 Privilege escalation through improper token-scope validation
CVE-2026-42018 JFrog Artifactory 7.5 Unauthenticated access to an internal anonymous-user token
CVE-2026-84869 ConnectWise ScreenConnect 9.9 Unauthorized file transfer and execution
CVE-2026-67277 MikroTik RouterOS 8.8 Kernel memory disclosure and denial of service
CVE-2026-86060 MikroTik RouterOS 9.2 Trusted-policy modification and privilege escalation

Artifactory Flaws Used to Gain Admin Access

The two Artifactory vulnerabilities are particularly concerning because attackers have been observed chaining them with CVE-2026-82329, another critical Artifactory vulnerability.

According to Wiz, attackers used the flaws to bypass authentication and escalate privileges, followed by post-exploitation activity including:

  • Creating persistent administrator accounts
  • Deploying malicious Groovy plugins
  • Executing commands on compromised servers
  • Installing Rust-based backdoors

The observed attacks occurred between August 15 and September 8, 2026, targeting unpatched self-hosted Artifactory installations.

ScreenConnect Flaw Enables Unauthorized File Execution

CVE-2026-84869 affects the ScreenConnect client and has a CVSS score of 9.9.

Under certain circumstances, an attacker can transfer files to and execute them on a connected host without authorization or host confirmation.

Huntress linked exploitation of the vulnerability to three incidents in which attackers used ScreenConnect to distribute a malicious VBScript payload to newly connected systems.

ConnectWise recommends upgrading to ScreenConnect 26.6.5. The vulnerability does not affect ScreenConnect servers.

MikroTik RouterOS Devices Targeted

CISA also added two RouterOS vulnerabilities following research from CERT Polska, which observed attackers exploiting the flaws to take control of vulnerable MikroTik devices without authentication.

The researchers referred to the exploitation chain as MikroTrick.

CVE-2026-67277 can expose kernel memory and cause denial-of-service conditions, while CVE-2026-86060 can allow attackers to modify the trusted RouterOS policy mask and escalate privileges.

Because MikroTik routers are frequently exposed at network boundaries, successful exploitation could provide attackers with a foothold for traffic interception, network reconnaissance or further compromise.

CISA Sets Aggressive Deadlines

CISA has assigned the following remediation deadlines for U.S. federal civilian agencies:

  • RouterOS vulnerabilities: September 13, 2026
  • ScreenConnect vulnerability: September 14, 2026
  • Artifactory vulnerabilities: September 25, 2026

Although these deadlines specifically apply to federal agencies, organizations operating the affected products should treat the KEV additions as a high-priority patching signal, particularly for internet-facing systems.

Recommended Actions

Security teams should:

  • Patch all affected Artifactory, ScreenConnect and RouterOS installations immediately.
  • Prioritize systems directly exposed to the internet.
  • Review logs for exploitation attempts and suspicious administrative activity.
  • Investigate unexpected Artifactory administrator accounts and plugins.
  • Look for unauthorized ScreenConnect clients, file transfers and script execution.
  • Review MikroTik configuration and policy changes.
  • Rotate credentials and tokens if compromise is suspected.
  • Hunt for post-exploitation activity after patching.

The latest KEV additions reinforce an important point for defenders: a vulnerability's presence in CISA's KEV catalog means organizations should prioritize remediation based on observed exploitation—not simply the CVSS score.

SEO Meta Description:
CISA adds five actively exploited Artifactory, ScreenConnect and MikroTik RouterOS vulnerabilities to its KEV catalog following real-world attacks and urges rapid remediation.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

critical CVE-2026-5430 Vulnerabilities

Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens

Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.

critical CVE-2026-85046, CVE-2026-87491 and CVE-2 Vulnerabilities

China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor

China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.