CVE Tools
Back to feed
Exploited in the wild JFrog Artifactory privilege-escalation ConnectWise ScreenConnect JFrog network-edge

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

CISA has designated five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS within its Known Exploited Vulnerabilities catalog. The flagged issues include CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, CVE-2026-84869 in ConnectWise ScreenConnect, and CVE-2026-67277 and CVE-2026-86060 in MikroTik RouterOS.

These additions follow observed attack chains where adversaries leveraged these flaws to gain unauthorized administrative access, deploy backdoors, and execute malicious payloads on targeted infrastructure. Federal agencies have been directed to remediate the specific vulnerabilities by strict deadlines ranging from September 13 to September 25, 2026.