CISA Adds Five Actively Exploited Vulnerabilities in JFrog Artifactory, ScreenConnect, and MikroTik RouterOS to KEV Catalog

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. This action follows reports of active exploitation of these flaws in the wild, highlighting the urgency for organizations to address these security issues.

Details of the vulnerabilities include:

  • CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token’s scope.
  • CVE-2026-42018 (CVSS score: 7.5) – An improper authentication vulnerability in JFrog Artifactory that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially leaking sensitive resources.
  • CVE-2026-84869 (CVSS score: 9.9) – An improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect that could allow an attacker to file transfer and execute through an active remote session without authorization or host confirmation.
  • CVE-2026-67277 (CVSS score: 8.8) – A missing authentication for a critical function vulnerability in MikroTik RouterOS that could allow kernel memory disclosure and denial-of-service in the btest service.
  • CVE-2026-86060 (CVSS score: 9.2) – An improper neutralization of argument delimiters in a command vulnerability in MikroTik RouterOS that could allow an attacker to change the trusted RouterOS policy mask and achieve privilege escalation.

According to reporting by The Hacker News, attackers have been observed chaining these vulnerabilities to bypass authentication and escalate privileges, gaining administrative control over vulnerable Artifactory instances. This includes the creation of persistent administrator accounts and the deployment of malicious plugins for code execution.

In a related incident, the exploitation of CVE-2026-84869 has been linked to three separate cases where threat actors used ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. ConnectWise has described this flaw as a condition that may allow unauthorized file transfers and execution through an active remote session.

CISA’s addition of CVE-2026-67277 and CVE-2026-86060 follows a report from CERT Polska, which noted that unknown threat actors exploited two flaws in MikroTik RouterOS to seize control of devices without authentication. The cybersecurity agency has mandated that federal agencies patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

NASA seeks proposals to advance lunar surface technologies for exploration

NASA is seeking proposals to advance the technology and infrastructure needed to explore the Moon and establish a Moon Base in the lunar South...

Concurrent attacks prompt reevaluation of air-and-missile-defense strategies

Recent conflicts have highlighted the effectiveness of air-and-missile-defense (AMD) systems in countering waves of cruise missiles and drone swarms. However, the rapid depletion of...

OpenAI Agents Linked to May Hacking Campaign Involving Malicious RubyGems Packages

Researchers have identified thousands of malicious software packages uploaded to RubyGems, a public repository for the Ruby programming language, by a group of OpenAI...

Cyberattackers exploit AI hype with phishing campaigns impersonating platforms like ChatGPT and Claude

Recent research from Microsoft Threat Intelligence reveals a surge in cyberattacks leveraging the hype surrounding artificial intelligence (AI). Cybercriminals are increasingly impersonating well-known AI...