CISA Adds 5 Exploited Artifactory, ScreenConnect, RouterOS Bugs to KEV

By Central

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. These vulnerabilities—ranging from privilege escalation in artifact management systems to remote code execution in popular remote desktop and router firmware—underscore a persistent trend in which threat actors chain multiple bugs to achieve full system compromise. The additions, announced on September 11 and 10, 2026, impose binding deadlines on Federal Civilian Executive Branch (FCEB) agencies, but the implications stretch far beyond government networks into enterprise IT, managed service providers, and critical infrastructure.

CISA Adds Five Exploited Vulnerabilities to KEV: What You Need to Know

CISA’s KEV catalog serves as a mandatory patching directive for federal agencies under Binding Operational Directive (BOD) 22-01, but it also functions as an authoritative alert for the broader cybersecurity community. The five newly listed CVEs span three widely used products: JFrog Artifactory (two flaws), ConnectWise ScreenConnect (one flaw), and MikroTik RouterOS (two flaws). Each has been confirmed as exploited in real-world attacks, with some incidents dating as far back as August 2026.

Below is a breakdown of each vulnerability:

  • CVE-2026-42016 (CVSS 8.1, High) – Incorrect authorization in JFrog Artifactory. The flaw allows privilege escalation because the software validates a token’s signature and issuer but does not check the token’s scope. An attacker with a valid token for a low-privilege account could escalate to higher privileges.
  • CVE-2026-42018 (CVSS 7.5, High) – Improper authentication in JFrog Artifactory. When anonymous access is disabled, the software may still return an internal anonymous-user token to an unauthenticated caller, potentially leaking sensitive resources such as repository metadata or artifacts.
  • CVE-2026-84869 (CVSS 9.9, Critical) – Improper privilege management and missing authorization in ConnectWise ScreenConnect. The flaw allows file transfer and execution through an active remote session without authorization or host confirmation, effectively enabling an attacker to push malware to a connected system.
  • CVE-2026-67277 (CVSS 8.8, High) – Missing authentication for a critical function in MikroTik RouterOS. The btest service (bandwidth test) can be triggered without authentication, leading to kernel memory disclosure and denial-of-service conditions.
  • CVE-2026-86060 (CVSS 9.2, Critical) – Improper neutralization of argument delimiters in a command in MikroTik RouterOS. An attacker can modify the trusted RouterOS policy mask, enabling privilege escalation—potentially from an unauthenticated position to full administrative control.

Each of these entries now carries a specific remediation deadline: MikroTik RouterOS flaws must be patched by September 13, 2026; the ScreenConnect flaw by September 14, 2026; and the Artifactory flaws by September 25, 2026. While these dates apply strictly to FCEB agencies, security teams in private organizations should treat them as urgent milestones given the confirmed active exploitation.

How Attackers Chained Two JFrog Artifactory Bugs with a Third Critical Flaw

Perhaps the most sophisticated attack chain among the newly added vulnerabilities involves JFrog Artifactory. Security researchers from Wiz, a cloud security firm acquired by Google, observed a campaign between August 15 and September 8, 2026, in which attackers combined CVE-2026-42016, CVE-2026-42018, and a previously listed vulnerability—CVE-2026-82329 (CVSS 9.8, Critical)—to take administrative control of self-hosted Artifactory servers. CVE-2026-82329 had already been added to CISA’s KEV catalog earlier in September 2026.

The attack flow worked as follows:

  • First, CVE-2026-42018 allowed an unauthenticated attacker to retrieve an internal anonymous-user token even when anonymous access was disabled. This token could then be used to query Artifactory APIs that should have been restricted.
  • Second, CVE-2026-42016 enabled privilege escalation from the anonymous token’s low-level permissions to a higher privilege level, because the token validation skipped scope checks.
  • Third, CVE-2026-82329—a critical vulnerability in Artifactory’s authentication mechanism—allowed the attacker to bypass authentication entirely and gain administrative privileges.

Wiz’s post-exploitation observations included the creation of persistent administrator accounts, the deployment of malicious Groovy plugins to execute arbitrary code on the server, and the installation of Rust-based backdoors designed to maintain long-term access. “Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances,” Wiz said. The Rust backdoors, in particular, are notable because they are more difficult to detect and analyze than traditional PowerShell or Python payloads.

Artifactory is a central repository manager used by thousands of organizations to store, manage, and distribute software artifacts—including container images, Maven packages, and npm modules. A compromise of an Artifactory server can lead to supply-chain attacks, where backdoored artifacts are distributed to internal development teams or even external customers. The chained exploitation therefore represents a severe risk to software supply chain integrity.

ScreenConnect Flaw Used to Distribute Malicious VBScript Payloads

The ConnectWise ScreenConnect vulnerability, CVE-2026-84869, has been exploited in at least three unrelated incidents documented by Huntress, a managed detection and response provider. In each case, threat actors abused an active ScreenConnect remote session to transfer a malicious Visual Basic Script (VBScript) payload to newly connected systems. The attack did not require any additional authorization or host confirmation from the user or administrator of the target machine.

ConnectWise described the flaw as a “condition” in the ScreenConnect client that “may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances.” Critically, the vulnerability affects only the ScreenConnect client—the server-side component remains untouched. This means that an attacker who already has an active remote session (perhaps obtained through a previous compromise or by tricking a support technician) can silently push files to the host system.

Huntress elaborated on the implications in an update: “Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions.” The firm urged all organizations using ScreenConnect to update to version 26.6.5, which contains the fix. Because ScreenConnect is widely deployed by managed service providers (MSPs) for remote support, a single compromised technician session could cascade into mass exploitation across dozens or hundreds of client environments.

MikroTik RouterOS Exploitation: The MikroTrick Campaign

The two MikroTik RouterOS vulnerabilities—CVE-2026-67277 and CVE-2026-86060—were documented by CERT Polska, the Polish national computer emergency response team. In a report released the week of September 7, 2026, CERT Polska described a campaign it dubbed MikroTrick, in which unknown threat actors exploited both flaws to seize control of vulnerable MikroTik routers without authentication.

MikroTik RouterOS powers millions of routers and wireless access points globally, particularly in small businesses, ISPs, and critical infrastructure environments. The btest service, targeted by CVE-2026-67277, is a standard bandwidth testing feature that, when exploited, can reveal kernel memory addresses (information leakage) and crash the system (denial of service). CVE-2026-86060, meanwhile, allows an attacker to change the trusted policy mask—essentially rewriting the device’s security policy—leading to privilege escalation from a limited access level to full administrative control.

Combined, the two flaws enable a remote, unauthenticated attacker to first gain a foothold (via memory disclosure and DoS potential) and then escalate privileges to compromise the device entirely. CERT Polska’s observation that the exploitation occurred “without authentication” underscores the severity: no password or prior access was required. Once a router is compromised, attackers can use it as a pivot point to scan internal networks, intercept traffic, launch further attacks, or recruit the device into a botnet.

What Is the Known Exploited Vulnerabilities Catalog and How Does It Work?

CISA’s Known Exploited Vulnerabilities (KEV) catalog is a centralized list of vulnerabilities that are known to be actively exploited in the wild. Under Binding Operational Directive 22-01, all federal civilian agencies must remediate listed vulnerabilities within specific timeframes—typically 14, 21, or 30 days depending on severity. While private sector organizations are not legally bound by the directive, the catalog is widely used as a prioritization tool: if CISA adds a vulnerability, security teams should treat it as an urgent patching priority because adversaries are already weaponizing it.

The catalog is updated regularly based on threat intelligence from CISA, the FBI, the NSA, and cybersecurity industry partners. Each entry includes the CVE identifier, a brief description, the date added, the due date for federal agencies, and a note on exploitation status. By listing a vulnerability, CISA signals that exploitation is confirmed—not merely theoretical. The five vulnerabilities added this week join hundreds of others, but the clustering of critical flaws in three distinct product categories highlights the breadth of attack surfaces that threat actors are currently targeting.

Why These Vulnerabilities Matter Beyond Federal Agencies

The deadlines for FCEB agencies—September 13, 14, and 25—are strict, but the impact of these vulnerabilities extends into virtually every sector. JFrog Artifactory is used by large enterprises, including many Fortune 500 companies, for managing software development pipelines. A compromise in Artifactory can inject malicious code into the software supply chain, affecting downstream customers. ConnectWise ScreenConnect is a backbone of remote IT support for MSPs, meaning a single exploited session can lead to rapid lateral movement across client networks. MikroTik RouterOS runs on routers deployed in hotels, ISPs, retail chains, and even some industrial control systems; compromise of such devices can result in persistent network-level access that is difficult to detect.

Organizations that use any of these products should immediately check their versions and apply the respective patches. For Artifactory, the critical CVE-2026-82329 was already added to KEV earlier this month, and the new flaws are part of the same attack chain—so simply patching one may not be sufficient. ScreenConnect users must upgrade to version 26.6.5 or later. MikroTik users should update RouterOS to the latest stable release that addresses both CVE-2026-67277 and CVE-2026-86060.

Practical Steps for Security Teams

Beyond patching, security teams should consider the following actions:

  • Audit Artifactory instances: Check for any unauthorized administrator accounts, unexpected Groovy plugins, and suspicious outbound connections. Wiz’s report indicates that attackers created persistent accounts and deployed Rust backdoors—look for processes with unusual names or file hashes that match Rust binaries.
  • Review ScreenConnect session logs: Examine active and past remote sessions for any file transfers that occurred without explicit user consent. Huntress noted that the VBScript payload was distributed during active sessions; logs may show unexpected script execution events.
  • Inventory MikroTik devices: Identify all RouterOS devices on the network and verify that the btest service is either disabled or restricted to authenticated users. Consider implementing firewall rules to limit management access to trusted IPs only.
  • Update incident response plans: Given that exploitation of these vulnerabilities can lead to full system takeover, prepare for potential data exfiltration, ransomware deployment, or lateral movement. Backup critical systems and ensure that detection rules for known indicators of compromise are in place.

The rapid addition of five vulnerabilities to the KEV catalog within a single week reflects the fast-moving nature of current threats. Attackers are not simply spraying exploits; they are chaining bugs across authentication, authorization, and privilege boundaries in ways that bypass traditional defenses. For defenders, the lesson is clear: patching must be both comprehensive and rapid, and security monitoring must account for multi-step attack chains that might initially appear as isolated incidents.

Future Outlook: Supply Chain and Remote Access Under Siege

These five CVEs, when taken together, illustrate two broader trends. First, supply chain tools like Artifactory are becoming prime targets because compromising them provides a force multiplier effect—a single breach can poison software used by hundreds of organizations. Second, remote access platforms like ScreenConnect are increasingly exploited as entry points, especially as MSPs and IT support teams continue to rely on them for day-to-day operations. The MikroTik flaws, meanwhile, highlight that even networking hardware—often considered “appliance” and not frequently patched—is now a regular focus for threat actors. As the deadlines for federal agencies pass, we can expect to see follow-up reports on how quickly—or slowly—the broader industry responds. The inclusion of these vulnerabilities in CISA’s KEV catalog is not a warning; it is a confirmation that the attacks are already happening. The question is whether organizations will act before they become victims.

Share This Article