CISA KEV Addition: Actively Exploited Artifactory, ScreenConnect, and RouterOS Vulnerabilities
First seen Sep 13, 2026 · Updated Sep 13, 2026 · CVSS 8.1
CISA has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. These flaws are being exploited in the wild, prompting federal agencies to remediate under mandated timelines. Organizations using these products, including those supporting DevOps and CI/CD pipelines, face elevated risk of compromise.
Technical Analysis
One of the disclosed flaws, CVE-2026-42016 (CVSS 8.1), is an incorrect authorization vulnerability, with the remaining four affecting ScreenConnect remote access software and MikroTik RouterOS firmware, though full CVE details for those were not provided in the source data. JFrog Artifactory is widely used as an artifact and package repository manager in software supply chains, meaning exploitation could enable attackers to tamper with or exfiltrate build artifacts, dependencies, and container images. ScreenConnect flaws have historically been leveraged for initial access and remote code execution by ransomware affiliates and initial access brokers, while RouterOS vulnerabilities are frequently exploited to build botnets or gain network-level footholds. Active exploitation confirmed by CISA indicates these are not theoretical risks but are being weaponized in current attack campaigns. Given that AI agent development pipelines often rely on Artifactory or similar repositories to pull dependencies, packages, and models, compromise of these systems could enable supply-chain attacks that inject malicious code into agent frameworks, RAG pipelines, or tool-use libraries, making this agent-relevant.
Affected Systems
JFrog Artifactory (versions affected by CVE-2026-42016, incorrect authorization flaw), ConnectWise ScreenConnect (specific vulnerable versions not detailed in source), MikroTik RouterOS (specific vulnerable versions not detailed in source)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source data; organizations should monitor CISA KEV catalog and vendor advisories for updated indicators.
Remediation Steps
- 1
Apply Vendor Patches Immediately
Update JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to the latest patched versions addressing the identified CVEs as soon as vendor fixes are available.
- 2
Review CISA KEV Catalog
Consult the official CISA KEV catalog entry for full CVE details, affected version ranges, and mandated remediation deadlines for federal agencies, and align internal patching SLAs accordingly.
- 3
Audit Authorization Controls
For Artifactory instances, review access control configurations and authorization policies to identify any exploitation of the incorrect authorization flaw (CVE-2026-42016).
- 4
Restrict External Exposure
Limit internet-facing access to ScreenConnect and RouterOS management interfaces, enforcing VPN or allowlisted access where possible.
- 5
Monitor Supply Chain Integrity
For organizations using Artifactory in CI/CD or AI/ML pipelines, audit recently published artifacts, packages, and container images for unauthorized modifications or unexpected changes.
- 6
Enable Logging and Threat Hunting
Increase logging on affected systems and hunt for indicators of unauthorized access, privilege escalation, or lateral movement consistent with known exploitation patterns for these products.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.