CISA Adds 5 Actively Exploited Artifactory, ScreenConnect and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog.

The additions follow reports of exploitation in the wild, including attacks that used the Artifactory flaws to gain administrative access and RouterOS vulnerabilities to take control of network devices.
Five Vulnerabilities Added
| CVE | Product | CVSS | Impact |
|---|---|---|---|
| CVE-2026-42016 | JFrog Artifactory | 8.1 | Privilege escalation through improper token-scope validation |
| CVE-2026-42018 | JFrog Artifactory | 7.5 | Unauthenticated access to an internal anonymous-user token |
| CVE-2026-84869 | ConnectWise ScreenConnect | 9.9 | Unauthorized file transfer and execution |
| CVE-2026-67277 | MikroTik RouterOS | 8.8 | Kernel memory disclosure and denial of service |
| CVE-2026-86060 | MikroTik RouterOS | 9.2 | Trusted-policy modification and privilege escalation |
Artifactory Flaws Used to Gain Admin Access
The two Artifactory vulnerabilities are particularly concerning because attackers have been observed chaining them with CVE-2026-82329, another critical Artifactory vulnerability.
According to Wiz, attackers used the flaws to bypass authentication and escalate privileges, followed by post-exploitation activity including:
- Creating persistent administrator accounts
- Deploying malicious Groovy plugins
- Executing commands on compromised servers
- Installing Rust-based backdoors
The observed attacks occurred between August 15 and September 8, 2026, targeting unpatched self-hosted Artifactory installations.
ScreenConnect Flaw Enables Unauthorized File Execution
CVE-2026-84869 affects the ScreenConnect client and has a CVSS score of 9.9.
Under certain circumstances, an attacker can transfer files to and execute them on a connected host without authorization or host confirmation.
Huntress linked exploitation of the vulnerability to three incidents in which attackers used ScreenConnect to distribute a malicious VBScript payload to newly connected systems.
ConnectWise recommends upgrading to ScreenConnect 26.6.5. The vulnerability does not affect ScreenConnect servers.
MikroTik RouterOS Devices Targeted
CISA also added two RouterOS vulnerabilities following research from CERT Polska, which observed attackers exploiting the flaws to take control of vulnerable MikroTik devices without authentication.
The researchers referred to the exploitation chain as MikroTrick.
CVE-2026-67277 can expose kernel memory and cause denial-of-service conditions, while CVE-2026-86060 can allow attackers to modify the trusted RouterOS policy mask and escalate privileges.
Because MikroTik routers are frequently exposed at network boundaries, successful exploitation could provide attackers with a foothold for traffic interception, network reconnaissance or further compromise.
CISA Sets Aggressive Deadlines
CISA has assigned the following remediation deadlines for U.S. federal civilian agencies:
- RouterOS vulnerabilities: September 13, 2026
- ScreenConnect vulnerability: September 14, 2026
- Artifactory vulnerabilities: September 25, 2026
Although these deadlines specifically apply to federal agencies, organizations operating the affected products should treat the KEV additions as a high-priority patching signal, particularly for internet-facing systems.
Recommended Actions
Security teams should:
- Patch all affected Artifactory, ScreenConnect and RouterOS installations immediately.
- Prioritize systems directly exposed to the internet.
- Review logs for exploitation attempts and suspicious administrative activity.
- Investigate unexpected Artifactory administrator accounts and plugins.
- Look for unauthorized ScreenConnect clients, file transfers and script execution.
- Review MikroTik configuration and policy changes.
- Rotate credentials and tokens if compromise is suspected.
- Hunt for post-exploitation activity after patching.
The latest KEV additions reinforce an important point for defenders: a vulnerability's presence in CISA's KEV catalog means organizations should prioritize remediation based on observed exploitation—not simply the CVSS score.
SEO Meta Description:
CISA adds five actively exploited Artifactory, ScreenConnect and MikroTik RouterOS vulnerabilities to its KEV catalog following real-world attacks and urges rapid remediation.
Related reporting
Hackers Exploit Critical WSO2 API Manager JWT Flaw Using Forged Admin Tokens
Security researchers have detected active exploitation attempts targeting a critical authentication-bypass vulnerability in WSO2 API Manager, with attackers sending forged JSON Web Tokens (JWTs) containing administrator privileges.
Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Code Feature
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could allow a nearby attacker to execute unauthorized code or access information stored on the console.
China-Linked Hackers Chain Chrome and Windows Zero-Days to Deploy GRIMWEDGE Backdoor
China-linked threat actors have been observed chaining multiple vulnerabilities in Google Chrome and Microsoft Windows as part of sophisticated cyber-espionage campaigns targeting non-governmental organizations and other high-value organizations.


