CISA names 5 KEV vulnerabilities in Artifactory, ScreenConnect and RouterOS with active exploitation

Author: Published 6 min de lectura 18 reading

The images in this article were generated with artificial intelligence. How we publish

The US Agency for Infrastructure and Cybersecurity. USA (CISA) has included five critical vulnerabilities that affect JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS in their catalogue of Known Exploited Vulnerabilities (KEV). This confirms that, in addition to laboratory failures, there are active incidents in which attackers are exploiting these weaknesses to obtain administrative control or persistence in corporate systems and network devices.

What has happened (confirmed facts). CISA has listed the following failures: two in JFrog Artifactory (CVE-2026-42016 and CVE-2026-42018), one in ConnectWise ScreenConnect (CVE-2026-84869) and two in MikroTik RouterOS (CVE-2026-67277 and CVE-2026-86060). Public reports from security companies and response groups indicate active exploitation: Wiz researchers and press reports documented exploitation chains against Artifactory that allowed for administrative control and backdoors; Huntress documented incidents in which ScreenConnect was abused to distribute and run VBScript payloads; and CERT Polska described an exploitation chain against RouterOS that allows for unauthenticated control (nicknamed "MikroTrick"). CISA has set mandatory remedies for federal agencies: RouterOS for September 13, 2026, ScreenConnect for September 14, 2026 and Artifactory for September 25, 2026.

CISA names 5 KEV vulnerabilities in Artifactory, ScreenConnect and RouterOS with active exploitation
Image generated with IA.

How vulnerabilities work technically (technical explanation verified). In Artifactory, a vulnerability of authorization and a vulnerability of authentication allow an attacker to skip tokens scope controls (scope) and, in certain cases, to obtain an internal anonymous token even if anonymous access is disabled - this makes it possible to raise privileges and, when combined with another already registered failure (CVE-2026-82329), to achieve full administrative access. The observed attackers have created persistent administrative accounts and deployed malicious plugins (Groovy) and backdoors compiled in Rust to maintain persistence. In ScreenConnect, the problem is in the host client: under certain conditions the client allows files to be transferred and executed without the typical host authorization, which enabled attackers to deliver and launch VBScript on newly connected equipment. In RouterOS, a vulnerability in the btest service allows for the disclosure of memory of the kernel and denial of service due to the absence of authentication, and another failure in the processing of command arguments allows to alter the confidence policy mask, leading to the escalation of privileges and control of the device.

Who it affects and what the real risk is. It affects organizations that use self-hosting JFrog Artifactory instances, customers that run the ConnectWise ScreenConnect component and networks that depend on routers and devices with MikroTik RouterOS exposed (especially if management services are accessible from the Internet). The risk is high: the CVSS assigned to these failures range from 7.5 to 9.9, and documented incidents show that they can lead to administrative control, backdoors and side movements in corporate environments. For critical infrastructure and environments with sensitive data, exploitation may mean loss of integrity and confidentiality, operational interruptions and exposure of development secrets (in the case of Artifactory, device repositories and embedded credentials).

What is confirmed and what remains uncertain. It is confirmed that CISA added these CVE to its KEV catalogue and that there are actual exploitation incidents reported by researchers (Wiz, Huntress, CERT Polska). It is also confirmed that the farms have included creation of administrative accounts and deployment of malware in Artifactory, and delivery of VBScript via ScreenConnect in specific cases. What is not fully publicly confirmed is the global reach - how many organizations have been committed in total -, the final attribution of the actors behind the campaigns and the availability of standardized and complete commitment indicators (IoC) in all cases; research continues and could reveal more vectors or related actors.

Specific and immediate measures to be taken by the reader (verifiable actions). First, park without delay: apply the official patches and updates indicated by the suppliers for the affected CVE (see the safety pages of JFrog, ConnectWise and MikroTik). If you cannot park immediately, reduce the exposure area: block public access to management ports and at the request of Artifactory, apply access control lists (ACL) and firewalls to allow only known IP ranges, and disable unnecessary services (e.g. btest in RouterOS) until the correction is applied. For ScreenConnect, update to the supplier's recommended version (Huntress recommends 26.6.5 to mitigate the host client problem) and review settings to require host confirmation and file transfer limits. In Artifactory, review the tokens management configuration and audit installed administrative accounts and plugins; look for unauthorized Groovy plugins and newly created accounts. Rote credentials and service keys that could have been exposed and enable multifactor authentication (MFA) in administrative panels.

CISA names 5 KEV vulnerabilities in Artifactory, ScreenConnect and RouterOS with active exploitation
Image generated with IA.

In addition, do a search for post-exploitation devices: examine access logs and administrative events, detect changes in repositories (load of devices or plugins), and look for unusual processes or binary (e.g., backdoors compiled in Rust). If you have EDR / NDR capabilities, create rules for detecting VBScript scripts from ScreenConnect sessions and for creating local accounts or administrative privilege elevations. Prepare a response plan that includes compromised systems isolation, secure password reimposition and backup integrity verification before restoring services.

Additional context and strategic recommendations. These vulnerabilities exemplify two recurring problems: errors in the validation of tokens / reach on development platforms and failures in the security of remote and network management components. Organizations should strengthen controls on access to development tools and repositories (network segmentation, MFA, regular review of privileged accounts) and minimize the exposure of administrative interfaces to the Internet. Introduce an agile patch management process and prioritize patches listed in the CISA KEV catalogue can reduce the risk window in sensitive sectors. To follow official publications and emergency notices, see the CISA page and the manufacturers' safety sections: CISA KEV, JFrog Security, ConnectWise Security and MikroTik Security. Additional reports and technical analysis were published by firms that investigated the incidents, including Wiz, Huntress and CERT Polska which can provide practical indicators and recommendations.

In summary, the inclusion of these vulnerabilities in the KEV catalogue and the active exploitation observations underline the need to treat these failures as an operational priority. The combination of immediate patch application, access restrictions, audit configurations and preparation of an incident response is the most effective way to mitigate risk while investigations continue.

Coverage

Related

More news on the same subject.