CISA Flags Critical Flaws in Artifactory, ScreenConnect, and RouterOS: Urgent Patching Required
CISA Flags Five Critical Flaws in Artifactory, ScreenConnect, and RouterOS as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five actively exploited security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog on September 12, 2026.
The additions signal a sharp escalation in real-world attacks targeting enterprise development tools, remote access platforms, and network infrastructure. With federal agencies already facing hard patch deadlines and threat actors chaining multiple flaws to seize administrative control, the window for organizations to act is narrowing fast. Understanding your exposure begins with a thorough assessment of vulnerabilities across your infrastructure — particularly when attackers are moving at this pace.
What the Five Vulnerabilities Involve
The five newly cataloged flaws carry severity scores ranging from 7.5 to 9.9 on the CVSS scale, reflecting serious risks across affected platforms. Each vulnerability represents a distinct attack surface, and together they expose three of the most widely deployed categories of enterprise technology: artifact management, remote access, and network routing.
JFrog Artifactory: Two Flaws Targeting Authorization and Authentication
Two vulnerabilities affect JFrog Artifactory. CVE-2026-42016, scored at 8.1, involves incorrect authorization that could lead to privilege escalation by exploiting a validation gap in token signature checks. CVE-2026-42018, scored at 7.5, involves improper authentication that could expose an internal anonymous-user token to unauthenticated callers even when anonymous access is explicitly disabled.
The combination of these two flaws is particularly dangerous because neither requires the attacker to hold a valid account — they are designed to circumvent the very controls organizations believe are protecting them.
ConnectWise ScreenConnect: A Near-Perfect CVSS Score
One critical flaw targets ConnectWise ScreenConnect. CVE-2026-84869 carries a near-perfect CVSS score of 9.9 and allows an attacker to transfer and execute files through an active remote session without authorization or host confirmation. ConnectWise described the issue as a "condition" in the ScreenConnect client that does not affect ScreenConnect servers.
That distinction matters operationally — but it offers limited comfort given the severity of what an attacker can do once a session is established.
MikroTik RouterOS: The "MikroTrick" Exploit Chain
Two vulnerabilities impact MikroTik RouterOS. CVE-2026-67277, scored at 8.8, enables kernel memory disclosure and denial-of-service through the btest service due to missing authentication. CVE-2026-86060, scored at 9.2, allows attackers to manipulate the trusted RouterOS policy mask and escalate privileges through improper handling of argument delimiters.
CERT Polska dubbed the RouterOS exploit chain "MikroTrick" after observing unknown threat actors using it to seize control of vulnerable devices without authentication. The name reflects both the sophistication and the deliberate sequencing of the two flaws — a pattern that has become a hallmark of mature, organized threat campaigns.
How Attackers Are Chaining These Flaws
The Artifactory vulnerabilities are not being exploited in isolation. According to Google-owned cloud security firm Wiz, attackers have been observed chaining CVE-2026-42016 and CVE-2026-42018 alongside a previously cataloged flaw, CVE-2026-82329 (CVSS score: 9.8), in a coordinated campaign running between August 15 and September 8, 2026.
"Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances," Wiz stated. "Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence."
CVE-2026-82329 was added to CISA's KEV catalog earlier in September 2026. The back-to-back additions underline how quickly threat actors are weaponizing newly disclosed flaws in widely deployed developer infrastructure. Staying ahead of these campaigns requires more than reactive patching — organizations benefit from embedding proactive cyber threat intelligence practices into their security operations to detect emerging chained attack patterns before exploitation reaches their environment.
The ScreenConnect Incidents
The ScreenConnect vulnerability tells a parallel story. Cybersecurity firm Huntress documented three separate and unrelated incidents in which threat actors exploited CVE-2026-84869 to distribute a malicious Visual Basic Script payload to newly connected systems.
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress noted.
The firm urged organizations to update immediately to ScreenConnect version 26.6.5. The three documented incidents — unconnected to one another — suggest opportunistic exploitation at scale rather than a single targeted campaign, which broadens the threat significantly.
Why Chained Attacks Are Harder to Detect and Stop
What makes these campaigns particularly disruptive is the sequencing. Attackers are not relying on a single critical flaw; they are combining authentication bypasses with privilege escalation techniques and long-term persistence mechanisms. By the time an initial alert fires, the attacker may already hold administrative access and have installed a backdoor designed to survive remediation.
This is not accidental. Threat actors targeting enterprise platforms like Artifactory and RouterOS are operating with a clear objective: establish access, escalate quietly, and remain undetected long enough to achieve their goals — whether that means data exfiltration, lateral movement, or infrastructure sabotage.
Modern threat actors are proving equally persistent in their approach — chaining authentication bypasses with privilege escalation and backdoor installation to ensure they maintain access even after initial detection. A structured vulnerability management process is no longer optional for organizations running any of these platforms; it is a foundational requirement for maintaining operational resilience.
Patch Deadlines and What Organizations Must Do
CISA has imposed firm remediation deadlines for Federal Civilian Executive Branch (FCEB) agencies. The MikroTik RouterOS flaws must be patched by September 13, 2026. The ScreenConnect vulnerability deadline falls on September 14, 2026. The two Artifactory flaws carry a slightly longer runway with a deadline of September 25, 2026.
While these mandates apply directly to federal agencies, private sector organizations running any of the affected platforms face comparable exposure. The combination of high CVSS scores, confirmed in-the-wild exploitation, and attacker techniques designed for persistence makes delayed patching a significant operational risk.
Immediate Actions for Security and IT Teams
The incidents documented across Artifactory, ScreenConnect, and RouterOS share a common thread: attackers are moving quickly from initial access to long-term persistence. Organizations relying on these platforms should treat the KEV listing not as a bureaucratic notice but as an active threat indicator requiring an immediate operational response.
Security and IT teams should audit all instances of JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS immediately, cross-referencing installed versions against the affected ranges for each CVE. Given the severity scores and documented multi-incident exploitation, CVE-2026-84869 and the RouterOS flaws warrant priority attention before the September 25 deadline for the Artifactory vulnerabilities arrives.
Equally important is reviewing post-exploitation indicators flagged by Wiz and Huntress — including unexpected administrator account creation, new Groovy plugins, and anomalous remote session activity — to determine whether a compromise may already be underway. For broader guidance on responding to active exploitation campaigns of this nature, CISA's Known Exploited Vulnerabilities catalog provides continuously updated information on cataloged flaws and recommended mitigations.
The pace at which these vulnerabilities have been weaponized — and the sophistication with which they are being chained — leaves little room for a measured, low-urgency response. Organizations should act now.