top of page
background.jpg

​

Cybersecurity Threat Intelligence Summary: CISA KEV Additions

Sep 21
1 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. Threat actors are actively weaponizing these vulnerabilities in the wild to bypass authentication, escalate privileges, and compromise critical infrastructure.



Vulnerability Breakdown and Exploitation Activity

  • JFrog Artifactory (CVE-2026-42016 & CVE-2026-42018):

o  CVE-2026-42016 (CVSS 8.1)

o   CVE-2026-42018 (CVSS 7.5)

  • ConnectWise ScreenConnect (CVE-2026-84869 - CVSS 9.9):

  • MikroTik RouterOS (CVE-2026-67277 & CVE-2026-86060):

o   CVE-2026-67277 (CVSS 8.8)

o   CVE-2026-86060 (CVSS 9.2


CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies resolve the RouterOS vulnerabilities by September 13, 2026, the ScreenConnect vulnerability by September 14, 2026, and the Artifactory vulnerabilities by September 25, 2026.


Key Precautions and Mitigation Measures

  • Upgrade ConnectWise ScreenConnect Client

  • Apply JFrog Artifactory Updates

  • Update MikroTik RouterOS Firmware

  • Audit Active Remote Sessions and Host Authorizations


For detailed information, you can reach out to our experts at info@zerosecond.com.ae .

 
 
 

Comments


bottom of page