CISA Adds Actively Exploited Flaws in Artifactory, ScreenConnect, and RouterOS to KEV Catalog
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities catalog. These flaws affect widely used platforms and are reportedly being exploited in the wild.
TL;DR
- CISA adds five new actively exploited vulnerabilities to its KEV list.
- Affected products include JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
- Organizations should prioritize patching due to active exploitation.
- One flaw has a CVSS score of 8.1, indicating high severity.
- Immediate action is recommended to mitigate potential breaches.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) continues to track and respond to threats targeting enterprise software systems by regularly updating its Known Exploited Vulnerabilities (KEV) catalog. In its latest update, CISA has added five security flaws that are currently being exploited in real-world attacks.
These newly listed vulnerabilities impact popular platforms including JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Given their active exploitation, organizations using these technologies are strongly advised to apply patches or implement mitigations as soon as possible to reduce exposure.
Vulnerability Overview
- CVE-2026-42016 affects JFrog Artifactory with a CVSS score of 8.1 due to incorrect authorization.
- Other vulnerabilities impact ConnectWise ScreenConnect and MikroTik RouterOS.
- All five flaws have been confirmed as under active exploitation.
- They were added to the KEV catalog to highlight critical risk to federal and private sector entities.
Recommended Actions
- Review systems for affected versions of Artifactory, ScreenConnect, and RouterOS.
- Apply vendor-released patches immediately where available.
- Monitor network traffic for signs of compromise related to these vulnerabilities.
- Use CISA's KEV catalog as part of vulnerability prioritization workflows.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.