The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active exploitation attempts. The newly listed flaws include issues related to authentication, authorization, privilege management, and command execution that could allow attackers to gain unauthorized access, escalate privileges, or compromise affected systems. CISA’s KEV catalog tracks vulnerabilities that are actively being exploited and provides organizations with guidance to prioritize security updates and mitigation measures.
Among the newly added vulnerabilities are two flaws affecting JFrog Artifactory, a platform widely used for managing software packages and development resources. CVE-2026-42016, with a CVSS score of 8.1, is an incorrect authorization vulnerability that could enable privilege escalation due to weaknesses in token validation. The issue occurs because the system validates token signature and issuer information but does not properly verify the token scope. Another vulnerability, CVE-2026-42018, carries a CVSS score of 7.5 and involves improper authentication handling. Under certain conditions, the flaw could allow an unauthenticated user to obtain an internal anonymous-user token even when anonymous access has been disabled, potentially exposing sensitive resources. Security researchers have previously reported attackers chaining these Artifactory vulnerabilities with CVE-2026-82329, a separate critical flaw, to gain administrative control of self-hosted servers. Observed activity included creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, and installing Rust-based backdoors to maintain access.
CISA also added CVE-2026-84869 affecting ConnectWise ScreenConnect, which has a CVSS score of 9.9 and involves improper privilege management and missing authorization controls. The vulnerability could allow unauthorized file transfers and execution through an active remote session without proper host confirmation in certain situations. According to security researchers, the flaw has been linked to multiple incidents where threat actors used compromised ScreenConnect environments to distribute malicious Visual Basic Script payloads to newly connected systems. ConnectWise described the issue as a condition within the ScreenConnect client that may allow files to be transferred and executed through active remote sessions under specific circumstances. The company clarified that ScreenConnect servers are not impacted by this vulnerability and recommended users update to ScreenConnect version 26.6.5 to address the issue.
The remaining two vulnerabilities added to the KEV catalog affect MikroTik RouterOS and have been linked to active exploitation attempts. CVE-2026-67277, rated 8.8 on the CVSS scale, involves missing authentication for a critical function and could allow attackers to disclose kernel memory or cause denial of service through the btest service. CVE-2026-86060, with a CVSS score of 9.2, involves improper handling of command arguments and could allow attackers to modify the trusted RouterOS policy mask and achieve privilege escalation. The addition of these flaws follows findings from CERT Polska, which reported that unknown threat actors were exploiting two RouterOS vulnerabilities to gain control of vulnerable devices without authentication. The exploit activity was tracked as MikroTrick. Following the additions, Federal Civilian Executive Branch (FCEB) agencies have been assigned deadlines to apply security updates. Agencies are required to address the RouterOS vulnerabilities by September 13, 2026, the ScreenConnect vulnerability by September 14, 2026, and the Artifactory vulnerabilities by September 25, 2026. Security teams are being encouraged to prioritize remediation efforts for these vulnerabilities due to confirmed exploitation activity and the potential impact on enterprise systems, development environments, and network infrastructure.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





