Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws Added to CISA's KEV Catalog



The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are required to patch these vulnerabilities by specific deadlines to prevent potential cyber attacks.

  • US CISA has added 5 actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
  • These vulnerabilities impact JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
  • CVE-2026-42016 in JFrog Artifactory has a CVSS score of 8.1 and can lead to privilege escalation and administrative control.
  • CVE-2026-42018 in JFrog Artifactory has a CVSS score of 7.5 and can leak sensitive resources.
  • CVE-2026-84869 in ConnectWise ScreenConnect allows file transfer and execution without authorization.
  • CVE-2026-67277 in MikroTik RouterOS has a CVSS score of 8.8 and can cause kernel memory disclosure and denial-of-service.
  • CVE-2026-86060 in MikroTik RouterOS has a CVSS score of 9.2 and can lead to privilege escalation.
  • Federal agencies must patch these vulnerabilities by September 13, 2026 (RouterOS), September 14, 2026 (ScreenConnect), and September 25, 2026 (Artifactory).



  • The cybersecurity landscape has recently witnessed a significant development with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding five actively exploited vulnerabilities impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. This move underscores the urgent need for organizations to patch these vulnerabilities and prevent potential cyber attacks.

    The vulnerabilities in question include:

    CVE-2026-42016 - An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's scope. This flaw has a CVSS score of 8.1 and has been chained alongside other vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances. According to Google-owned Wiz, attackers have observed post-exploitation activity such as the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence.

    CVE-2026-42018 - An improper authentication vulnerability in JFrog Artifactory that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially leaking sensitive resources. This flaw also has a CVSS score of 7.5.

    CVE-2026-84869 - An improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect that could allow an attacker to file transfer and execute through an active remote session without authorization or host confirmation. The exploitation of this vulnerability has been linked to a set of three unrelated incidents documented by Huntress, where threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions. The issue does not impact ScreenConnect servers.

    CVE-2026-67277 - A missing authentication for a critical function vulnerability in MikroTik RouterOS that could allow kernel memory disclosure and denial-of-service in the btest service. This flaw has a CVSS score of 8.8.

    CVE-2026-86060 - An improper neutralization of argument delimiters in a command vulnerability in MikroTik RouterOS that could allow an attacker to change the trusted RouterOS policy mask and achieve privilege escalation. This flaw has a CVSS score of 9.2.

    The addition of these vulnerabilities to CISA's KEV catalog is a stark reminder of the need for organizations to prioritize their cybersecurity posture. As CISA notes, attackers have been observed chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances. Furthermore, the exploitation of CVE-2026-84869 has been linked to a set of three unrelated incidents documented by Huntress, where threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.

    Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026. It is imperative that these agencies take immediate action to address these vulnerabilities and prevent potential cyber attacks.

    In conclusion, the addition of these actively exploited vulnerabilities to CISA's KEV catalog underscores the urgent need for organizations to patch these vulnerabilities and prevent potential cyber attacks. It is essential that organizations prioritize their cybersecurity posture and take immediate action to address these vulnerabilities.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Actively-Exploited-Artifactory-ScreenConnect-and-RouterOS-Flaws-Added-to-CISAs-KEV-Catalog-ehn.shtml

  • https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-42016

  • https://www.cvedetails.com/cve/CVE-2026-42016/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-42018

  • https://www.cvedetails.com/cve/CVE-2026-42018/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-84869

  • https://www.cvedetails.com/cve/CVE-2026-84869/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-67277

  • https://www.cvedetails.com/cve/CVE-2026-67277/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-86060

  • https://www.cvedetails.com/cve/CVE-2026-86060/


  • Published: Sat Sep 12 13:22:30 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us