CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog.
The additions follow reports that threat actors are actively exploiting the flaws in real-world attacks.
JFrog Artifactory Vulnerabilities
CVE-2026-42016
CVSS Score: 8.1
This incorrect authorization vulnerability could allow privilege escalation. The issue occurs because Artifactory validates a token's signature and issuer but does not properly verify its scope.
CVE-2026-42018
CVSS Score: 7.5
This improper authentication vulnerability could allow an unauthenticated attacker to obtain an internal anonymous-user token, even when anonymous access is disabled. The issue could expose sensitive resources.
Attackers have reportedly chained these two vulnerabilities with CVE-2026-82329, a critical flaw with a CVSS score of 9.8, to gain administrator control of self-hosted Artifactory servers.
Observed post-exploitation activity includes:
- Creating persistent administrator accounts.
- Deploying malicious Groovy plugins for code execution.
- Installing Rust-based backdoors.
- Establishing long-term access to compromised servers.
The exploitation activity was observed between August 15 and September 8, 2026.
ConnectWise ScreenConnect Vulnerability
CVE-2026-84869
CVSS Score: 9.9
This vulnerability involves improper privilege management and missing authorization in ConnectWise ScreenConnect.
Under certain conditions, an attacker may be able to transfer and execute files through an active remote session without authorization or confirmation from the host.
The vulnerability has been linked to three incidents in which threat actors used ScreenConnect to distribute a malicious Visual Basic Script payload to newly connected systems.
ConnectWise stated that the issue affects the ScreenConnect client and does not impact ScreenConnect servers.
Organizations are urged to update ScreenConnect to version 26.6.5.
MikroTik RouterOS Vulnerabilities
CVE-2026-67277
CVSS Score: 8.8
This missing authentication vulnerability affects the RouterOS bandwidth-test service, also known as btest.
Successful exploitation could allow attackers to disclose kernel memory and cause denial-of-service conditions.
CVE-2026-86060
CVSS Score: 9.2
This command-injection-related vulnerability involves improper handling of argument delimiters.
An attacker could exploit the flaw to modify the trusted RouterOS policy mask and achieve privilege escalation.
The addition of these vulnerabilities follows a report from CERT Polska, which observed threat actors exploiting RouterOS flaws to take control of vulnerable MikroTik devices without authentication. The exploit chain was named MikroTrick.
CISA Patch Deadlines for Federal Agencies
CISA has set the following remediation deadlines for Federal Civilian Executive Branch agencies:
- MikroTik RouterOS vulnerabilities: September 13, 2026
- ConnectWise ScreenConnect vulnerability: September 14, 2026
- JFrog Artifactory vulnerabilities: September 25, 2026
Organizations using the affected products should apply the available security updates immediately and review their systems for signs of unauthorized access, privilege escalation, persistence, or malicious file execution.