CISA Adds Critical JFrog, ConnectWise, and MikroTik Flaws to KEV Catalog Amid Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a critical alert, adding five new vulnerabilities impacting **JFrog Artifactory**, **ConnectWise ScreenConnect**, and **MikroTik RouterOS** to its Known Exploited Vulnerabilities (**KEV**) catalog. These additions come after confirmed reports of active exploitation in the wild, urging immediate action from IT security professionals and organizations.
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has added five security flaws impacting **JFrog Artifactory**, **ConnectWise ScreenConnect**, and **MikroTik RouterOS** to its Known Exploited Vulnerabilities (**KEV**) catalog, following reports of active exploitation in the wild.
### The Newly Cataloged Vulnerabilities
Details of the vulnerabilities are as follows:
* **CVE-2026-42016** (CVSS score: 8.1) - An incorrect authorization vulnerability in **JFrog Artifactory** that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's scope.
* **CVE-2026-42018** (CVSS score: 7.5) - An improper authentication vulnerability in **JFrog Artifactory** that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially leaking sensitive resources.
* **CVE-2026-84869** (CVSS score: 9.9) - An improper privilege management and missing authorization vulnerability in **ConnectWise ScreenConnect** that could allow an attacker to file transfer and execute through an active remote session without authorization or host confirmation.
* **CVE-2026-67277** (CVSS score: 8.8) - A missing authentication for a critical function vulnerability in **MikroTik RouterOS** that could allow kernel memory disclosure and denial-of-service in the btest service.
* **CVE-2026-86060** (CVSS score: 9.2) - An improper neutralization of argument delimiters in a command vulnerability in **MikroTik RouterOS** that could allow an attacker to change the trusted RouterOS policy mask and achieve privilege escalation.
### Chained Exploits Targeting JFrog Artifactory
Attackers have been observed chaining the two **Artifactory** bugs (**CVE-2026-42016** and **CVE-2026-42018**) alongside **CVE-2026-82329** (CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors. This activity was noted between August 15 and September 8, 2026. **CVE-2026-82329** was previously added to **CISA**'s **KEV** catalog earlier this month.
"Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable **Artifactory** instances," stated **Google**-owned **Wiz**. "Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence."
### ConnectWise ScreenConnect Under Attack
Exploitation of **CVE-2026-84869** has been linked to three unrelated incidents documented by **Huntress**. Threat actors abused **ScreenConnect** to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
**ConnectWise** described the flaw as a "condition" in the **ScreenConnect** client that "may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances." It's important to note that this issue does not impact **ScreenConnect** servers.
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," **Huntress** noted in an update, urging organizations to update to **ScreenConnect** version 26.6.5.
### MikroTik RouterOS Flaws: The MikroTrick Exploit Chain
**CISA**'s addition of **CVE-2026-67277** and **CVE-2026-86060** follows a report from **CERT Polska** last week. **CERT Polska** observed unknown threat actors exploiting these two flaws in **MikroTik RouterOS** to seize control of vulnerable devices without authentication, dubbing the exploit chain **MikroTrick**.
### CISA Mandates Patching Deadlines
Federal Civilian Executive Branch (FCEB) agencies are required to patch the **RouterOS** flaws by September 13, 2026, the **ScreenConnect** flaw by September 14, 2026, and the **Artifactory** flaws by September 25, 2026.