{"id":18660,"date":"2026-09-12T21:01:13","date_gmt":"2026-09-12T21:01:13","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=18660"},"modified":"2026-09-12T21:01:13","modified_gmt":"2026-09-12T21:01:13","slug":"cisa-provides-5-actively-exploited-artifactory-screenconnect-and-routeros-flaws-to-kev","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=18660","title":{"rendered":"CISA Provides 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 12, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Safety<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhva55LDIsAmtR2cRnUJw2XZ3Rvo4YhdJe39cfng8EZ1oHjLevxwRcYoFdg-ydI2I7fdt9OxGj7aMcaHMekZmy9hwSlopIZ4_KQgRnmiSy0OfGh8zO26StiEeOsHaQ4fYed0dbEUCUcz4gJM9Lu6Wt7m-ppDmI7iMl52-cRfQfsu9d90Sp2ncuvbVpAPupe\/s1600\/jj.jpg\" style=\"display: block; padding: 1em 0; text-align: center; clear: left; float: left;\"><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"470\" data-original-width=\"900\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhva55LDIsAmtR2cRnUJw2XZ3Rvo4YhdJe39cfng8EZ1oHjLevxwRcYoFdg-ydI2I7fdt9OxGj7aMcaHMekZmy9hwSlopIZ4_KQgRnmiSy0OfGh8zO26StiEeOsHaQ4fYed0dbEUCUcz4gJM9Lu6Wt7m-ppDmI7iMl52-cRfQfsu9d90Sp2ncuvbVpAPupe\/s1600\/jj.jpg\"\/><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has added 5 safety flaws impacting <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/11\/cisa-adds-three-known-exploited-vulnerabilities-catalog\" target=\"_blank\">JFrog Artifactory, ConnectWise ScreenConnect<\/a>, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/10\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">MikroTik RouterOS<\/a> to its Recognized Exploited Vulnerabilities (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, following studies of lively exploitation within the wild.<\/p>\n<p>Particulars of the vulnerabilities are as follows &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-42016<\/strong> (CVSS rating: 8.1) &#8211; An incorrect authorization vulnerability in JFrog Artifactory that would result in privilege escalation resulting from a validation examine of the token signature\/issuer and never the token&#8217;s scope.<\/li>\n<li><strong>CVE-2026-42018<\/strong> (CVSS rating: 7.5) &#8211; An improper authentication vulnerability in JFrog Artifactory that would return an inner anonymous-user token to an unauthenticated caller when nameless entry is disabled, probably leaking delicate assets.<\/li>\n<li><strong>CVE-2026-84869<\/strong> (CVSS rating: 9.9) &#8211; An improper privilege administration and lacking authorization vulnerability in\u00a0 ConnectWise ScreenConnect that would enable an attacker to file switch and execute by means of an lively distant session with out authorization or host affirmation.<\/li>\n<li><strong>CVE-2026-67277<\/strong> (CVSS rating: 8.8) &#8211; A lacking authentication for a essential perform vulnerability in\u00a0 MikroTik RouterOS that would enable kernel reminiscence disclosure and denial-of-service within the btest service.<\/li>\n<li><strong>CVE-2026-86060<\/strong> (CVSS rating: 9.2) &#8211; An improper neutralization of argument delimiters in a command vulnerability in\u00a0 MikroTik RouterOS that would enable an attacker to alter the trusted RouterOS coverage masks and obtain privilege escalation.<\/li>\n<\/ul>\n<p>As <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-chain-jfrog-artifactory-flaws.html\" target=\"_blank\">beforehand reported<\/a> by The Hacker Information, attackers have been noticed chaining the 2 Artifactory bugs alongside <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-exploit-critical-jfrog.html\" target=\"_blank\">CVE-2026-82329<\/a> (CVSS rating: 9.8) to take administrator management of self-hosted servers and deploy backdoors between August 15 and September 8, 2026. CVE-2026-82329 was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/09\/cisa-adds-seven-exploited-flaws-as.html\" target=\"_blank\">added<\/a> to CISA&#8217;s KEV catalog earlier this month.<\/p>\n<p><!--adsense--><\/p>\n<p>&#8220;Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and acquire administrative management over susceptible Artifactory cases,&#8221; Google-owned Wiz mentioned. &#8220;Noticed post-exploitation exercise consists of the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the set up of Rust-based backdoors to determine persistence.&#8221;<\/p>\n<p>The exploitation of CVE-2026-84869, however, has been linked to a set of three unrelated incidents <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/09\/rogue-screenconnect-clients-spread-four.html\" target=\"_blank\">documented<\/a> by Huntress through which risk actors abused ScreenConnect to distribute a malicious Visible Primary Script (VBScript) payload to newly related methods.<\/p>\n<p>ConnectWise has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-09-08-screenconnect-bulletin\" target=\"_blank\">described<\/a> the flaw as a &#8220;situation&#8221; within the ScreenConnect shopper that &#8220;could enable information to be transferred and executed by means of an lively distant session with out authorization or Host affirmation in sure circumstances.&#8221; The difficulty doesn&#8217;t impression ScreenConnect servers.<\/p>\n<p>&#8220;Underneath sure circumstances, this might allow information to be transferred to and executed on the Host shopper system, together with by means of elevated execution actions,&#8221; Huntress <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.huntress.com\/blog\/rogue-screenconnect-installations\" target=\"_blank\">mentioned<\/a> in an replace, urging organizations to replace to ScreenConnect model 26.6.5.<\/p>\n<p>CISA&#8217;s addition of CVE-2026-67277 and CVE-2026-86060 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-hijack-mikrotik-routers.html\" target=\"_blank\">follows a report<\/a> from CERT Polska final week through which it mentioned it <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/09\/weekly-recap-chrome-0-day-router.html#:~:text=MikroTik%20RouterOS%20Flaws%20Exploited\" target=\"_blank\">noticed<\/a> unknown risk actors exploiting two flaws in MikroTik RouterOS to grab management of susceptible gadgets with out authentication. The cybersecurity company dubbed the exploit chain MikroTrick.<\/p>\n<p>Federal Civilian Government Department (FCEB) businesses are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 12, 2026Vulnerability \/ Enterprise Safety The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has added 5 safety flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Recognized Exploited Vulnerabilities (KEV) catalog, following studies of lively exploitation within the wild. Particulars of the vulnerabilities are as follows &#8211; CVE-2026-42016 (CVSS rating: 8.1) [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":18662,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1993,390,10523,1359,1994,1812,4988,10524,894],"class_list":["post-18660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-actively","tag-adds","tag-artifactory","tag-cisa","tag-exploited","tag-flaws","tag-kev","tag-routeros","tag-screenconnect"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18660"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18660\/revisions"}],"predecessor-version":[{"id":18661,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/18660\/revisions\/18661"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/18662"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}