Back to feed

CISA Adds Five Exploited Artifactory, ScreenConnect, RouterOS Flaws to KEV Catalog

2 min
CISA Adds Five Exploited Artifactory, ScreenConnect, RouterOS Flaws to KEV Catalog

This digest was compiled by AI from multiple sources — links to the originals are below.

The U.S. Cybersecurity and Infrastructure Security Agency added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. The move follows observed attacks chaining the flaws to take over servers and deploy backdoors between August 15 and September 8, 2026. The catalog now includes CVE-2026-82329, added earlier this month.

Key Facts

  • CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog on September 12, 2026.
  • The added flaws affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
  • Attackers chained the two Artifactory bugs with CVE-2026-82329 to gain administrator control and deploy backdoors between August 15 and September 8, 2026.
  • CVE-2026-84869 in ScreenConnect has a CVSS score of 9.9 and allows file transfer and execution without authorization.
  • Wiz observed post-exploitation activity including creation of persistent administrator accounts and deployment of Rust-based backdoors.

Vulnerability Details

CVE-2026-42016 in JFrog Artifactory has a CVSS score of 8.1 and allows privilege escalation due to incorrect authorization. CVE-2026-42018 in JFrog Artifactory has a CVSS score of 7.5 and can return an internal anonymous-user token to an unauthenticated caller. CVE-2026-84869 in ConnectWise ScreenConnect has a CVSS score of 9.9 and allows file transfer and execution through an active remote session without authorization. CVE-2026-67277 in MikroTik RouterOS has a CVSS score of 8.8 and can cause kernel memory disclosure and denial-of-service in the btest service. CVE-2026-86060 in MikroTik RouterOS has a CVSS score of 9.2 and allows changing the trusted RouterOS policy mask to achieve privilege escalation.

Exploitation Activity

Attackers chained the two Artifactory bugs with CVE-2026-82329 to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026. CVE-2026-82329 was added to CISA's KEV catalog earlier this month. Google-owned Wiz said attackers are chaining the vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances. Wiz observed post-exploitation activity including creation of persistent administrator accounts, deployment of malicious Groovy plugins, and installation of Rust-based backdoors. Huntress documented three unrelated incidents where threat actors abused ScreenConnect to distribute a malicious VBScript payload to newly connected systems.

Vendor Response

ConnectWise described CVE-2026-84869 as a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or host confirmation in certain circumstances. The issue does not impact ScreenConnect servers.

1 source

Time · lag behind first