The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently identified five critical security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog due to reports of active exploitation.
Details of the Newly Identified Vulnerabilities
The vulnerabilities include a range of issues such as incorrect authorization and improper authentication in JFrog Artifactory. Specifically, CVE-2026-42016 with a CVSS score of 8.1, and CVE-2026-42018 scoring 7.5. These could result in privilege escalation and unauthorized access to sensitive resources, respectively.
ConnectWise ScreenConnect is also affected by CVE-2026-84869, with a high severity score of 9.9. This flaw in privilege management allows file transfer and execution during a remote session without proper authorization.
Two significant vulnerabilities in MikroTik RouterOS, CVE-2026-67277 and CVE-2026-86060, have been reported. These vulnerabilities allow kernel memory disclosure and unauthorized policy changes, posing severe security risks.
Exploitation and Threats
According to security reports, attackers have been leveraging these vulnerabilities to gain unauthorized access and deploy backdoors, particularly in self-hosted servers using Artifactory bugs. This has involved chaining these vulnerabilities with another severe flaw, CVE-2026-82329, to establish persistent administrative control.
ConnectWise ScreenConnect’s vulnerability has been exploited in incidents where threat actors used it to distribute harmful scripts, affecting newly connected systems. Organizations are advised to update to the latest version to mitigate these risks.
Urgent Security Measures and Recommendations
CISA’s recent additions to the KEV catalog underline the urgent need for organizations to address these vulnerabilities promptly. CERT Polska has also reported active exploitation of MikroTik RouterOS flaws, urging immediate action to secure affected devices.
Federal Civilian Executive Branch (FCEB) agencies have been mandated to patch these vulnerabilities by specific deadlines to prevent potential security breaches. This includes updates for RouterOS by September 13, ScreenConnect by September 14, and Artifactory by September 25, 2026.
Organizations are strongly encouraged to assess their systems for these vulnerabilities and apply necessary patches to ensure robust cybersecurity defenses.
