The images in this article were generated with artificial intelligence. How we publish
The US Agency for Infrastructure and Cybersecurity. USA (CISA) has included five critical vulnerabilities that affect JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS in their catalogue of Known Exploited Vulnerabilities (KEV). This confirms that, in addition to laboratory failures, there are active incidents in which attackers are exploiting these weaknesses to obtain administrative control or persistence in corporate systems and network devices.
What has happened (confirmed facts). CISA has listed the following failures: two in JFrog Artifactory (CVE-2026-42016 and CVE-2026-42018), one in ConnectWise ScreenConnect (CVE-2026-84869) and two in MikroTik RouterOS (CVE-2026-67277 and CVE-2026-86060). Public reports from security companies and response groups indicate active exploitation: Wiz researchers and press reports documented exploitation chains against Artifactory that allowed for administrative control and backdoors; Huntress documented incidents in which ScreenConnect was abused to distribute and run VBScript payloads; and CERT Polska described an exploitation chain against RouterOS that allows for unauthenticated control (nicknamed "MikroTrick"). CISA has set mandatory remedies for federal agencies: RouterOS for September 13, 2026, ScreenConnect for September 14, 2026 and Artifactory for September 25, 2026.

How vulnerabilities work technically (technical explanation verified). In Artifactory, a vulnerability of authorization and a vulnerability of authentication allow an attacker to skip tokens scope controls (scope) and, in certain cases, to obtain an internal anonymous token even if anonymous access is disabled - this makes it possible to raise privileges and, when combined with another already registered failure (CVE-2026-82329), to achieve full administrative access. The observed attackers have created persistent administrative accounts and deployed malicious plugins (Groovy) and backdoors compiled in Rust to maintain persistence. In ScreenConnect, the problem is in the host client: under certain conditions the client allows files to be transferred and executed without the typical host authorization, which enabled attackers to deliver and launch VBScript on newly connected equipment. In RouterOS, a vulnerability in the btest service allows for the disclosure of memory of the kernel and denial of service due to the absence of authentication, and another failure in the processing of command arguments allows to alter the confidence policy mask, leading to the escalation of privileges and control of the device.
Who it affects and what the real risk is. It affects organizations that use self-hosting JFrog Artifactory instances, customers that run the ConnectWise ScreenConnect component and networks that depend on routers and devices with MikroTik RouterOS exposed (especially if management services are accessible from the Internet). The risk is high: the CVSS assigned to these failures range from 7.5 to 9.9, and documented incidents show that they can lead to administrative control, backdoors and side movements in corporate environments. For critical infrastructure and environments with sensitive data, exploitation may mean loss of integrity and confidentiality, operational interruptions and exposure of development secrets (in the case of Artifactory, device repositories and embedded credentials).
What is confirmed and what remains uncertain. It is confirmed that CISA added these CVE to its KEV catalogue and that there are actual exploitation incidents reported by researchers (Wiz, Huntress, CERT Polska). It is also confirmed that the farms have included creation of administrative accounts and deployment of malware in Artifactory, and delivery of VBScript via ScreenConnect in specific cases. What is not fully publicly confirmed is the global reach - how many organizations have been committed in total -, the final attribution of the actors behind the campaigns and the availability of standardized and complete commitment indicators (IoC) in all cases; research continues and could reveal more vectors or related actors.
Specific and immediate measures to be taken by the reader (verifiable actions). First, park without delay: apply the official patches and updates indicated by the suppliers for the affected CVE (see the safety pages of JFrog, ConnectWise and MikroTik). If you cannot park immediately, reduce the exposure area: block public access to management ports and at the request of Artifactory, apply access control lists (ACL) and firewalls to allow only known IP ranges, and disable unnecessary services (e.g. btest in RouterOS) until the correction is applied. For ScreenConnect, update to the supplier's recommended version (Huntress recommends 26.6.5 to mitigate the host client problem) and review settings to require host confirmation and file transfer limits. In Artifactory, review the tokens management configuration and audit installed administrative accounts and plugins; look for unauthorized Groovy plugins and newly created accounts. Rote credentials and service keys that could have been exposed and enable multifactor authentication (MFA) in administrative panels.

In addition, do a search for post-exploitation devices: examine access logs and administrative events, detect changes in repositories (load of devices or plugins), and look for unusual processes or binary (e.g., backdoors compiled in Rust). If you have EDR / NDR capabilities, create rules for detecting VBScript scripts from ScreenConnect sessions and for creating local accounts or administrative privilege elevations. Prepare a response plan that includes compromised systems isolation, secure password reimposition and backup integrity verification before restoring services.
Additional context and strategic recommendations. These vulnerabilities exemplify two recurring problems: errors in the validation of tokens / reach on development platforms and failures in the security of remote and network management components. Organizations should strengthen controls on access to development tools and repositories (network segmentation, MFA, regular review of privileged accounts) and minimize the exposure of administrative interfaces to the Internet. Introduce an agile patch management process and prioritize patches listed in the CISA KEV catalogue can reduce the risk window in sensitive sectors. To follow official publications and emergency notices, see the CISA page and the manufacturers' safety sections: CISA KEV, JFrog Security, ConnectWise Security and MikroTik Security. Additional reports and technical analysis were published by firms that investigated the incidents, including Wiz, Huntress and CERT Polska which can provide practical indicators and recommendations.
In summary, the inclusion of these vulnerabilities in the KEV catalogue and the active exploitation observations underline the need to treat these failures as an operational priority. The combination of immediate patch application, access restrictions, audit configurations and preparation of an incident response is the most effective way to mitigate risk while investigations continue.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. Accordin...