The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include five critical security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. This update comes in response to active exploitation incidents identified across various environments, raising concerns for organizations utilizing these platforms.
The discovered vulnerabilities present significant threats, particularly for JFrog Artifactory. One notable flaw, designated as CVE-2026-42016, has a CVSS score of 8.1, resulting from an erroneous authorization process that could enable privilege escalation. This undermines the validation of the token signature/issuer as it fails to adequately verify the token’s scope. Another concerning vulnerability, CVE-2026-42018, scoring 7.5, pertains to improper authentication within Artifactory. This flaw may unintentionally expose internal anonymous-user tokens to unauthenticated callers when anonymous access features are disabled, potentially allowing unauthorized access to sensitive resources.
ConnectWise ScreenConnect has been reported to have a particularly dangerous issue: CVE-2026-84869, which has a staggering CVSS score of 9.9 due to improper privilege management coupled with missing authorization layers. This vulnerability could permit attackers to transfer files and execute commands during an active remote session without requiring host confirmation or proper authorization. Similarly, MikroTik RouterOS is impacted by two vulnerabilities, CVE-2026-67277 and CVE-2026-86060, with CVSS scores of 8.8 and 9.2, respectively. These flaws expose critical functions that could lead to unauthorized kernel memory disclosure and allow attackers to manipulate RouterOS policy settings for privilege escalation purposes.
Reports have indicated that attackers are leveraging these vulnerabilities to chain attacks effectively. For instance, instances were documented where vulnerabilities within Artifactory were combined with CVE-2026-82329, which has a CVSS score of 9.8. This pairing enabled adversaries to assume administrative control over self-hosted servers, resulting in the deployment of backdoors and unauthorized scripts from August 15 to September 8, 2026.
The exploitation of the ConnectWise ScreenConnect vulnerability has also been associated with efforts to distribute malicious payloads through compromised systems, raising alarms about the potential for widespread impact across affected networks. ConnectWise itself has acknowledged this problem, identifying it as a condition that could permit file transfers without the necessary checks during remote sessions.
CISA’s inclusion of vulnerabilities found in MikroTik RouterOS emerged following findings from CERT Polska, illustrating how unidentified threat actors exploited two significant flaws within RouterOS to gain device control without user authentication. This campaign has been labeled as part of a more extensive effort dubbed “MikroTrick.”
For organizations operating within the U.S., compliance mandates stipulate that Federal Civilian Executive Branch (FCEB) agencies must address these vulnerabilities promptly; patches for the RouterOS flaws are required by September 13, ScreenConnect by September 14, and JFrog Artifactory by September 25. Business leaders must act swiftly, as these vulnerabilities present considerable risks that could be exploited by malicious actors, leveraging tactics outlined in the MITRE ATT&CK framework, particularly pertaining to initial access, privilege escalation, and persistence to maintain control over compromised systems.
Cybersecurity diligence is paramount, as the current vulnerabilities emphasize the critical need for continuous monitoring and timely updates to maintain secure operational environments.