started · updated
CISA adds five exploited flaws in Artifactory, ScreenConnect, and RouterOS to KEV catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited security flaws to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities impact JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
In the JFrog Artifactory ecosystem, attackers are reportedly chaining multiple vulnerabilities, including CVE-2026-42016 and CVE-2026-42018, to achieve administrative privilege escalation. These flaws allow for unauthorized access and the creation of administrative accounts, which can be used to install backdoors and malicious plugins. Researchers have noted that exploitation often occurs even after patches have been released.
Other critical flaws include CVE-2026-84869 in ConnectWise ScreenConnect, which carries a CVSS score of 9.9 and allows unauthorized file transfers and execution, and two vulnerabilities in MikroTik RouterOS (CVE-2026-67277 and CVE-2026-86060) that can lead to kernel memory disclosure, denial-of-service, and privilege escalation.
Entities
CISA · ConnectWise · ConnectWise ScreenConnect · Hugging Face · JFrog · JFrog Artifactory · MikroTik RouterOS · OpenAI · WatchTowr · Wiz
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] CVE-2026-86060 is a command vulnerability in MikroTik RouterOS that can allow privilege escalation. cybernoz.com · thehackernews.com
- [○ 1 SOURCE] Wiz security researchers confirmed in-the-wild exploitation of three JFrog Artifactory vulnerabilities across multiple environments. www.theregister.com
- [● 2 SOURCES] CVE-2026-84869 is an improper privilege management vulnerability in ConnectWise ScreenConnect with a CVSS score of 9.9. cybernoz.com · thehackernews.com
- [● 3 SOURCES] CISA added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. cybernoz.com · www.it-boltwise.de · thehackernews.com
- [● 2 SOURCES] CVE-2026-67277 is a missing authentication vulnerability in MikroTik RouterOS that can allow kernel memory disclosure. cybernoz.com · thehackernews.com
- [● 6 SOURCES] CVE-2026-42018 is an improper authentication vulnerability in JFrog Artifactory that can return an internal anonymous-user token to an unauthenticated caller. cybernoz.com · cybersecurity-news.de · www.it-boltwise.de · sempreupdate.com.br · www.theregister.com · +1 more
- [● 4 SOURCES] CVE-2026-42016 is an incorrect authorization vulnerability in JFrog Artifactory that can lead to privilege escalation. cybernoz.com · cybersecurity-news.de · www.it-boltwise.de · thehackernews.com
- [○ 1 SOURCE] Attackers using CVE-2026-82329 were observed enumerating users, groups, and credential sets. www.theregister.com