CISA has added five actively exploited flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog after reports that threat actors are actively abusing the bugs in the wild. The move forces a practical reprioritization for federal agencies and raises a short, sharp question for operators: are patches applied before the next chain is used?
The five CVEs CISA added and what they do
- CVE-2026-42016 (CVSS 8.1) — JFrog Artifactory: an incorrect authorization bug that can allow privilege escalation because the product validates token signature/issuer but not token scope.
- CVE-2026-42018 (CVSS 7.5) — JFrog Artifactory: an improper authentication issue that can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially leaking sensitive resources.
- CVE-2026-84869 (CVSS 9.9) — ConnectWise ScreenConnect: improper privilege management and missing authorization that could allow file transfer and execution through an active remote session without authorization or host confirmation.
- CVE-2026-67277 (CVSS 8.8) — MikroTik RouterOS: missing authentication for a critical function in the btest service, enabling kernel memory disclosure and denial-of-service.
- CVE-2026-86060 (CVSS 9.2) — MikroTik RouterOS: improper neutralization of argument delimiters in a command that can change the trusted RouterOS policy mask and enable privilege escalation.
Artifactory: chained attacks, backdoors, and persistent admin accounts
Multiple reports — including one cited by The Hacker News — document attackers chaining the two newly added Artifactory bugs alongside CVE-2026-82329 (CVSS 9.8), itself added to CISA's KEV catalog earlier this month. The observed activity between August 15 and September 8, 2026, shows attackers moving from initial bypasses to full administrative control of self-hosted Artifactory servers.
According to Wiz, post-exploitation activity has included creation of persistent administrator accounts, deployment of malicious Groovy plugins for remote code execution, and installation of Rust-based backdoors to ensure persistence. Those specific techniques — account creation, plugin-based code execution, and compiled backdoors — tell a consistent operational story: initial authentication failures are being turned quickly into durable footholds.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleConnectWise ScreenConnect: file-transfer condition and VBScript distribution
ConnectWise characterized CVE-2026-84869 as a "condition" in the ScreenConnect client that "may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances." The vendor said servers are not impacted.
Separate incident analysis by Huntress linked exploitation of this ScreenConnect client issue to three unrelated incidents in which attackers abused ScreenConnect to deliver a malicious Visual Basic Script (VBScript) payload to newly connected systems. Huntress urged organizations to update to ScreenConnect version 26.6.5 to address the problem.
MikroTik RouterOS and "MikroTrick": unauthenticated device takeover
CISA's additions for RouterOS, CVE-2026-67277 and CVE-2026-86060, follow a report from CERT Polska that said unknown threat actors had been exploiting two RouterOS flaws to seize control of devices without authentication. CERT Polska dubbed the exploit chain "MikroTrick."
The two RouterOS flaws have different technical effects but convergent operational consequences: CVE-2026-67277 allows kernel memory disclosure and denial-of-service via the btest service, while CVE-2026-86060 alters the trusted RouterOS policy mask through command-argument manipulation, enabling privilege escalation. Together, CERT Polska's observations and CISA's KEV listing indicate these are practical, not theoretical, avenues to device compromise.
What the Federal Civilian Executive Branch, security teams, and affected organizations should watch
- Federal Civilian Executive Branch (FCEB): CISA has set concrete patching deadlines — RouterOS flaws must be patched by September 13, 2026; the ScreenConnect flaw by September 14, 2026; and the Artifactory flaws by September 25, 2026. These are binding timelines for FCEB agencies.
- Security teams and technologists: observed chaining of Artifactory bugs with CVE-2026-82329 and the documented post-exploitation activity (persistent admin accounts, malicious Groovy plugins, Rust backdoors) mean defenders should search telemetry for account creation events, plugin installations, and unusual executable placement consistent with backdoor deployment.
- Affected vendors and enterprise operators (ConnectWise, JFrog, MikroTik customers): ConnectWise has advised that the ScreenConnect server is not impacted and that clients need patching; Huntress recommends updating to ScreenConnect 26.6.5. Enterprises running self-hosted Artifactory or RouterOS should prioritize the KEV-listed fixes accordingly.
The pattern is clear in the facts recorded so far: a mix of high-severity authorization and authentication failures, public exploitation observed by multiple security teams, and a set of imminent federal deadlines. Those three factors together make the calendar as consequential as any single technical detail — and they leave no comfortable margin for delay.
https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html




