CISA Adds Five Actively Exploited Artifactory, ScreenConnect, RouterOS Flaws to KEV
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog this week after confirming active exploitation across three widely deployed developer and IT-management platforms: JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. The Artifactory additions follow a detailed report from Wiz describing a real-world attack chain observed between August 15 and September 8, in which attackers combined two flaws to escalate from an unauthenticated request all the way to full administrator control of self-hosted Artifactory servers. Once administrator access was obtained, attackers created persistent admin accounts, installed malicious Groovy plugins to achieve code execution, and in several cases deployed a custom Rust-based backdoor for command-and-control. A related but separate Artifactory authentication bypass, exploited independently between September 1 and 8, was reportedly hit by hundreds of thousands of scanning attempts in a single day according to network telemetry shared by a content delivery provider. The ScreenConnect and RouterOS additions stem from independent incidents: rogue ScreenConnect clients being abused to push malicious script payloads to newly connected endpoints, and an exploit chain nicknamed by researchers that lets attackers seize control of exposed MikroTik routers without authentication.
Who is affected
Organizations running self-hosted JFrog Artifactory instances that have not applied the relevant security fixes are exposed to the admin-takeover chain; JFrog's SaaS/cloud offering is not affected. ConnectWise ScreenConnect client deployments used for remote access and support are affected by the file-transfer-and-execute issue, which impacts the client rather than the server component. MikroTik RouterOS devices exposed to untrusted networks, particularly those with management or diagnostic services reachable from the internet, are affected by the two flaws tied to kernel memory disclosure and policy-mask manipulation.
Why it matters
Artifactory sits inside the software build pipeline, meaning a compromised instance can be used to poison build artifacts, steal CI/CD credentials, or pivot into downstream systems that trust it — a textbook supply-chain risk. Because the administrator accounts and backdoors that attackers create typically survive a version upgrade, patching alone does not undo a prior compromise; affected organizations need to actively hunt for unauthorized accounts and rotate secrets. The ScreenConnect and RouterOS issues broaden the picture, showing that supply-chain and infrastructure risk this week spans build tooling, remote-access software, and network edge devices simultaneously — all now formally recognized by CISA as under real-world attack.
Technical details
- CVE-2026-42016 (CVSS 8.1) — Incorrect authorization in JFrog Artifactory; a token's signature and issuer are validated but not its scope, allowing a low-privilege token to be exchanged for an administrator-scope token.
- CVE-2026-42018 (CVSS 7.5) — Improper authentication in JFrog Artifactory that returns an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled.
- CVE-2026-84869 (CVSS 9.9) — Improper privilege management in ConnectWise ScreenConnect clients allowing file transfer and execution through an active remote session without authorization or host confirmation.
- CVE-2026-67277 (CVSS 8.8) — Missing authentication for a critical function in MikroTik RouterOS's btest service, enabling kernel memory disclosure and denial-of-service.
- CVE-2026-86060 (CVSS 9.2) — Improper neutralization of argument delimiters in RouterOS, allowing an attacker to alter the trusted policy mask and escalate privileges.
- A related, previously catalogued flaw, CVE-2026-82329 (CVSS 9.8), is a critical Artifactory authentication bypass exploited alongside the two flaws above to complete the admin-takeover chain.
- Federal remediation deadlines: RouterOS flaws by September 13, 2026; the ScreenConnect flaw by September 14, 2026; the Artifactory flaws by September 25, 2026.
Recommended actions
- Upgrade self-hosted JFrog Artifactory to the fixed build for your release branch as listed in JFrog's security advisories; cloud/SaaS Artifactory requires no action.
- Treat any Artifactory server that was exposed and unpatched during the attack window as potentially compromised: rotate the platform join key, revoke access tokens issued since late August, and review all administrator accounts, repositories, and configuration changes for unauthorized modifications.
- Look for administrator accounts you did not create, especially ones with generic or service-like names, and for actions logged under an anonymous or low-privilege identity performing administrator-level operations.
- Update ScreenConnect clients to the vendor's fixed version and audit recent remote sessions for unexpected file transfers or script execution.
- Restrict management and diagnostic interfaces on MikroTik RouterOS devices from the public internet, and apply RouterOS security updates as soon as they are available for your device.
- Cross-reference your exposed assets against the CISA KEV catalog and prioritize remediation using the published federal deadlines as a benchmark for urgency, even if you are not a federal agency.
Sources
- https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html
- https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html
