CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

Ravie LakshmananSep 12, 2026Vulnerability / Enterprise Security

\"\"

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities have been actively exploited in the wild, prompting CISA to include them in its Known Exploited Vulnerabilities (KEV) catalog.

The details of the vulnerabilities are as follows:

  • CVE-2026-42016 (CVSS score: 8.1) – Incorrect authorization vulnerability in JFrog Artifactory leading to privilege escalation.
  • CVE-2026-42018 (CVSS score: 7.5) – Improper authentication vulnerability in JFrog Artifactory potentially leaking sensitive resources.
  • CVE-2026-84869 (CVSS score: 9.9) – Privilege management and authorization vulnerability in ConnectWise ScreenConnect allowing unauthorized file transfer and execution.
  • CVE-2026-67277 (CVSS score: 8.8) – Missing authentication vulnerability in MikroTik RouterOS leading to kernel memory disclosure.
  • CVE-2026-86060 (CVSS score: 9.2) – Improper argument delimiters neutralization vulnerability in MikroTik RouterOS enabling privilege escalation.

Attackers have been exploiting these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable systems. The exploitation of these vulnerabilities has been associated with various malicious activities such as creating persistent administrator accounts, deploying malicious plugins, and establishing backdoors.

ConnectWise ScreenConnect vulnerability has been linked to incidents where threat actors distributed malicious payloads through active remote sessions. Organizations are urged to update to the latest version of ScreenConnect to mitigate this risk.

CISA has instructed Federal Civilian Executive Branch (FCEB) agencies to patch the identified vulnerabilities within specific timelines to enhance their cybersecurity posture and prevent potential exploitation.