VMTech
Discuss a project

CISA lists five exploited flaws in Artifactory, ScreenConnect and RouterOS

CISA lists five exploited flaws in Artifactory, ScreenConnect and RouterOS

CISA expands KEV catalog with five enterprise security flaws

The U.S. Cybersecurity and Infrastructure Security Agency has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. The additions cover two Artifactory issues, one ScreenConnect client issue and two RouterOS flaws.

The highest-rated newly listed vulnerability is CVE-2026-84869, with a CVSS score of 9.9. The ConnectWise ScreenConnect flaw involves improper privilege management and missing authorization, and could allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.

The two Artifactory vulnerabilities are CVE-2026-42016, rated 8.1, and CVE-2026-42018, rated 7.5. The first is an incorrect authorization issue involving validation of a token signature and issuer but not its scope, which can lead to privilege escalation. The second is an improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Observed attack chains and affected versions

Attackers have been observed chaining the two newly listed Artifactory bugs with CVE-2026-82329, rated 9.8, to obtain administrator control of self-hosted servers. Activity observed between August 15 and September 8 included persistent administrator accounts, malicious Groovy plugins used for code execution, and Rust-based backdoors. The KEV expansion follows CISA’s expanding exploited vulnerability catalog as CISA continues to highlight vulnerabilities with confirmed exploitation.

Wiz said the Artifactory chain can bypass authentication, escalate privileges and grant administrative control over vulnerable instances. CVE-2026-82329 had already been added to the KEV catalog earlier in September.

Huntress linked exploitation of the ScreenConnect issue to three unrelated incidents in which threat actors used the product to distribute a malicious Visual Basic Script payload to newly connected systems. ConnectWise described the issue as a condition in the ScreenConnect client that may permit file transfer and execution through an active remote session in certain circumstances. The issue does not affect ScreenConnect servers, and Huntress urged organizations to update to ScreenConnect version 26.6.5.

RouterOS exploitation and agency deadlines

CISA also added CVE-2026-67277, rated 8.8, and CVE-2026-86060, rated 9.2, affecting MikroTik RouterOS. The first is missing authentication for a critical function in the btest service and can enable kernel-memory disclosure and denial of service. The second involves improper neutralization of argument delimiters and may allow an attacker to alter a trusted RouterOS policy mask and escalate privileges.

CERT Polska reported that unknown threat actors exploited the two RouterOS flaws to take control of vulnerable devices without authentication, calling the exploit chain MikroTrick. Federal Civilian Executive Branch agencies must patch the RouterOS flaws by September 13, the ScreenConnect flaw by September 14, and the Artifactory flaws by September 25, 2026. Businesses should use these deadlines to prioritize asset discovery, verify affected versions and apply the available updates to internet-exposed and high-value systems.

#cybersecurity#vulnerability#patchmanagement#enterprisesecurity
Open analytics
On the site 0 views
min read 4 12.09.2026
Instagram

CISA lists five exploited flaws in Artifactory, ScreenConnect and RouterOS

Open the post on Instagram ↗