HackMyIP
← Back to News
2026-09-12 The Hacker News

CISA Adds 5 Actively Exploited Flaws Targeting Artifactory, ScreenConnect, RouterOS

VulnerabilityAuthenticationThreat Intel

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing confirmed in-the-wild exploitation. The flaws include CVE-2026-42016 and CVE-2026-42018 in Artifactory (CVSS 8.1 and 7.5), an incorrect authorization issue and an improper authentication flaw that can leak internal anonymous-user tokens to unauthenticated callers. Also listed are CVE-2026-84869 in ScreenConnect (CVSS 9.9), a privilege management flaw enabling unauthorized file transfer and execution during active remote sessions, plus CVE-2026-67277 and CVE-2026-86060 in RouterOS (CVSS 8.8 and 9.2), which expose kernel memory disclosure and a path to policy-mask manipulation for privilege escalation. Administrators can use a port scanner to quickly verify exposed management interfaces on affected appliances.

According to Google-owned Wiz, threat actors chained CVE-2026-42016 and CVE-2026-42018 alongside CVE-2026-82329 (CVSS 9.8, previously added to KEV) between August 15 and September 8, 2026, to seize administrator control of self-hosted Artifactory instances. Post-exploitation activity included the creation of persistent administrator accounts, deployment of malicious Groovy plugins for code execution, and installation of Rust-based backdoors to establish long-term persistence on compromised servers. Separately, Huntress linked exploitation of CVE-2026-84869 to three incidents in which attackers leveraged ScreenConnect to drop VBScript payloads onto newly connected hosts, taking advantage of a client-side condition that ConnectWise confirmed "may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances."

CISA has mandated that federal agencies remediate the listed flaws by the standard KEV deadline and is urging private-sector operators to do the same, given the public exploitation evidence. ConnectWise has issued patches for ScreenConnect 23.9.8 and later, while JFrog and MikroTik have published corresponding advisories for their affected builds. Defenders should audit administrative accounts, review remote session logs for unauthorized file transfers, rotate any credentials stored on compromised appliances, and confirm TLS configurations on exposed endpoints with an SSL/TLS checker. Network defenders monitoring MikroTik infrastructure can also benefit from a WHOIS lookup to verify the legitimacy of any newly observed outbound connections tied to the RouterOS exploitation activity.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →