TechNewsReel
Live

CISA Adds Six Actively Exploited Flaws in Artifactory, ScreenConnect, and RouterOS to KEV

Federal agencies face tight deadlines to patch critical infrastructure tools as CISA warns that simple patching may not be enough.

TechNewsReel Newsroom · September 12, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog between September 10 and 11, 2026. The additions target critical software from JFrog, ConnectWise, and MikroTik, with some requiring immediate forensic investigation to detect existing breaches.

On September 10, CISA added two MikroTik RouterOS flaws—CVE-2026-67277, involving information disclosure and denial of service, and CVE-2026-86060, which allows argument injection and privilege escalation—with a remediation deadline of September 13. On September 11, the agency added CVE-2026-84869 for ConnectWise ScreenConnect, which enables unauthorized file transfer and execution during active remote sessions, setting a deadline of September 14, 2026. Additionally, JFrog Artifactory vulnerabilities CVE-2026-42016 (Incorrect Authorization) and CVE-2026-42018 (Improper Authentication) were listed on September 11, with a deadline of September 25.

Infrastructure Under Fire

These additions arrive during a period of intensified targeting of supply chain and remote management tools. JFrog Artifactory has been the subject of a 24-day campaign, while MikroTik RouterOS has been hit by a series of zero-days targeting SSH services for router takeover, a trend F5 Labs has dubbed "MikroTrick."

Security research from Wiz indicates that attackers are not using the Artifactory flaws in isolation. Instead, they are chaining these vulnerabilities to deploy malicious Groovy plugins and Rust-based backdoors, allowing for persistent access to development environments.

The Risk of Administrative Takeover

Because Artifactory, ScreenConnect, and RouterOS operate at the core of corporate networking and software delivery, the stakes for exploitation are exceptionally high. These tools typically possess high-level system privileges, meaning a successful breach can grant an attacker full administrative control over the host system.

For organizations, this creates a pathway for widespread data exfiltration and the establishment of persistent backdoors across the internal network. The ability to execute unauthorized files via ScreenConnect or escalate privileges via RouterOS allows attackers to move laterally through a network with minimal resistance.

Beyond the Patch

CISA has emphasized that for several of these flaws, including the ScreenConnect vulnerability and RouterOS CVE-2026-86060, remediation cannot be treated as a simple patching exercise. The agency has identified forensic triage as a requirement, urging organizations to investigate affected devices for signs of compromise.

Security teams are advised to look for indicators of compromise (IoCs) that suggest a breach occurred before the patch was applied. As federal agencies race to meet deadlines that in some cases have already passed, the focus shifts to determining whether these critical gateways have already been weaponized by adversaries.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.