CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7141

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The affected products include JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, with CVE-2026-42016 (CVSS 8.1) involving an authorization flaw.

Why it matters: Organizations using Artifactory, ScreenConnect, or RouterOS face immediate risk from attackers actively exploiting these flaws and should prioritize patching or mitigation for these products.

VendorsConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog on September 12, 2026, based on confirmed active exploitation. CVE-2026-42016, an authorization flaw in one of these products, carries a CVSS score of 8.1.

Why it matters: Security teams using Artifactory, ScreenConnect, or RouterOS should prioritize patching these flaws immediately, as they are already being exploited in attacks and listed on CISA's KEV catalog.

VendorsConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary