CISA has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog. Attackers have been chaining these flaws to gain administrative control, deploy backdoors, and seize vulnerable devices without authentication. #JFrogArtifactory #ConnectWiseScreenConnect #MikroTikRouterOS #CVE-2026-42016 #CVE-2026-42018 #CVE-2026-84869 #CVE-2026-67277 #CVE-2026-86060 #CVE-2026-82329 #MikroTrick
Keypoints
- CISA added five exploited vulnerabilities to its KEV catalog.
- JFrog Artifactory flaws were used to bypass authentication and gain admin control.
- Attackers deployed persistent accounts, Groovy plugins, and Rust-based backdoors on Artifactory servers.
- ConnectWise ScreenConnect flaw could allow unauthorized file transfer and execution in active sessions.
- MikroTik RouterOS flaws were exploited in the MikroTrick chain to take over devices without authentication.
Read More: https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html