CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
- ID
- 23845
- Status
- summarized
- Published
- 12 Sep 2026, 11:54 PM
- Fetched
- 13 Sep 2026, 2:53 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 13 Sep 2026, 2:54 AM
- Tags
- Audience
- developersdatabase_learnerssaas_founders
What happened
CISA added five actively exploited vulnerabilities to its KEV catalog: two in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018) being chained with a third (CVE-2026-82329, CVSS 9.8) for admin takeover and Rust-based backdoor deployment on self-hosted servers, one critical ScreenConnect flaw (CVE-2026-84869, CVSS 9.9) allowing unauthorized file transfer and execution via active sessions, and two MikroTik RouterOS flaws (CVE-2026-67277, CVE-2026-86060) enabling kernel memory disclosure and privilege escalation. Active exploitation of the Artifactory chain was observed between August 15 and September 8, 2026.
Why it matters
If you run self-hosted Artifactory, patch immediately — attackers are chaining these three CVEs to create persistent admin accounts, deploy malicious Groovy plugins, and install Rust backdoors. MikroTik RouterOS devices are ubiquitous in Malaysian SMB and ISP networks; the two RouterOS flaws mean any unpatched MikroTik on your perimeter could expose kernel memory or be privilege-escalated. ScreenConnect users should update since the 9.9 CVSS flaw allows execution through an active session without host confirmation.
Discussion angle
How many teams in the audience actually run self-hosted Artifactory or MikroTik gear, and do they have a patch cadence for infrastructure tooling that isn't their own application code?