THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
The flaws are CVE-2026-42016 (8.1) in JFrog Artifactory, an incorrect authorisation flaw that can enable privilege escalation via token signature/issuer validation rather than the token’s scope; CVE-2026-42018 (7.5) also in Artifactory, an improper authentication issue that could return an internal anonymous-user token to unauthenticated callers when anonymous access is disabled, risking leakage of resources.
In ScreenConnect, CVE-2026-84869 (9.9) relates to improper privilege management that could allow file transfer and execution through an active remote session without authorisation or host confirmation.
MikroTik RouterOS is implicated by CVE-2026-67277 (8.8), a missing authentication flaw in the btest service that could cause kernel memory disclosure and a denial-of-service condition, and CVE-2026-86060 (9.2), improper neutralisation of argument delimiters in a command that could enable privilege escalation by changing the trusted RouterOS policy mask.
Observed exploitation chains link Artifactory flaws with CVE-2026-82329 (9.8) to seize administrator control and deploy backdoors, with ScreenConnect abuse connected to distributing a VBScript payload via the platform.
The exploit activity has been described by Wiz and Huntress as a pattern of authentication bypass, privilege escalation, and remote-control compromise, with attackers creating persistent administrator accounts, deploying malicious Groovy plugins, and installing Rust-based backdoors for persistence. The known incidents span August 15 to September 8, 2026.
Federal guidance requires patches by 15 September 2026 for ScreenConnect, 25 September 2026 for Artifactory, and 13 September 2026 for MikroTik RouterOS, with agencies urged to apply updates accordingly.