Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Highlights Critical Security Flaws in Artifactory and RouterOS

CISA Highlights Critical Security Flaws in Artifactory and RouterOS

Posted on September 12, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently identified five critical security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog due to reports of active exploitation.

Details of the Newly Identified Vulnerabilities

The vulnerabilities include a range of issues such as incorrect authorization and improper authentication in JFrog Artifactory. Specifically, CVE-2026-42016 with a CVSS score of 8.1, and CVE-2026-42018 scoring 7.5. These could result in privilege escalation and unauthorized access to sensitive resources, respectively.

ConnectWise ScreenConnect is also affected by CVE-2026-84869, with a high severity score of 9.9. This flaw in privilege management allows file transfer and execution during a remote session without proper authorization.

Two significant vulnerabilities in MikroTik RouterOS, CVE-2026-67277 and CVE-2026-86060, have been reported. These vulnerabilities allow kernel memory disclosure and unauthorized policy changes, posing severe security risks.

Exploitation and Threats

According to security reports, attackers have been leveraging these vulnerabilities to gain unauthorized access and deploy backdoors, particularly in self-hosted servers using Artifactory bugs. This has involved chaining these vulnerabilities with another severe flaw, CVE-2026-82329, to establish persistent administrative control.

ConnectWise ScreenConnect’s vulnerability has been exploited in incidents where threat actors used it to distribute harmful scripts, affecting newly connected systems. Organizations are advised to update to the latest version to mitigate these risks.

Urgent Security Measures and Recommendations

CISA’s recent additions to the KEV catalog underline the urgent need for organizations to address these vulnerabilities promptly. CERT Polska has also reported active exploitation of MikroTik RouterOS flaws, urging immediate action to secure affected devices.

Federal Civilian Executive Branch (FCEB) agencies have been mandated to patch these vulnerabilities by specific deadlines to prevent potential security breaches. This includes updates for RouterOS by September 13, ScreenConnect by September 14, and Artifactory by September 25, 2026.

Organizations are strongly encouraged to assess their systems for these vulnerabilities and apply necessary patches to ensure robust cybersecurity defenses.

The Hacker News Tags:Artifactory, CISA, Cybersecurity, exploited vulnerabilities, FCEB agencies, Patching, RouterOS, ScreenConnect, security flaws, Vulnerability

Post navigation

Previous Post: VLC Media Player Security Flaws Pose Serious Risks

Related Posts

Why Business Impact Should Lead the Security Conversation Why Business Impact Should Lead the Security Conversation The Hacker News
Botnet Uses Polygon Blockchain for Resilient Command Control Botnet Uses Polygon Blockchain for Resilient Command Control The Hacker News
Checkmarx Data Breach: GitHub Data Exposed on Dark Web Checkmarx Data Breach: GitHub Data Exposed on Dark Web The Hacker News
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign The Hacker News
Your First and Last Line of Defense Your First and Last Line of Defense The Hacker News
Ivanti Warns of Active Exploitation in EPMM Vulnerability Ivanti Warns of Active Exploitation in EPMM Vulnerability The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS
  • VLC Media Player Security Flaws Pose Serious Risks
  • Enhancing Security: Tackling Cloud Supply-Chain Threats
  • AI-Driven Cyber Threats Demand Swift Security Upgrades
  • BlueMoon Exploit Kit Targets Chrome and Windows Zero-Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark