The digital landscape is under constant threat, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning, adding five critical security flaws to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities, impacting widely used platforms such as JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, are not theoretical risks but are actively being exploited in the wild, demanding immediate attention from organizations worldwide.
JFrog Artifactory: A Gateway to Privilege Escalation
Two significant vulnerabilities in JFrog Artifactory have been identified, allowing attackers to bypass authentication and escalate privileges. These flaws, when chained together, have already led to severe breaches:
- CVE-2026-42016 (CVSS: 8.1): An incorrect authorization vulnerability that facilitates privilege escalation. The flaw stems from an inadequate validation check, focusing on the token’s signature/issuer rather than its scope.
- CVE-2026-42018 (CVSS: 7.5): An improper authentication vulnerability that can expose sensitive resources. This occurs when an unauthenticated caller receives an internal anonymous-user token, even if anonymous access is disabled.
As previously highlighted by The Hacker News, threat actors have been observed leveraging these two Artifactory bugs in conjunction with CVE-2026-82329 (CVSS: 9.8) to seize administrative control of self-hosted servers. This sophisticated attack chain, active between August 15 and September 8, 2026, has resulted in the deployment of persistent administrator accounts, malicious Groovy plugins for code execution, and Rust-based backdoors, as reported by Google-owned Wiz. CVE-2026-82329 was added to CISA’s KEV earlier this month, underscoring the ongoing nature of these threats.
ConnectWise ScreenConnect: Remote Execution Risks
ConnectWise ScreenConnect, a popular remote support solution, faces a critical flaw that could enable unauthorized file transfer and execution:
- CVE-2026-84869 (CVSS: 9.9): An improper privilege management and missing authorization vulnerability. This severe flaw allows attackers to transfer and execute files through an active remote session without requiring authorization or host confirmation.
Huntress has documented at least three separate incidents where threat actors exploited CVE-2026-84869 to distribute malicious Visual Basic Script (VBScript) payloads to newly connected systems. ConnectWise has clarified that this “condition” affects the ScreenConnect client, not the servers, and can facilitate file transfer and execution, including elevated actions, under specific circumstances. Organizations are strongly urged to update to ScreenConnect version 26.6.5 immediately to mitigate this risk.
MikroTik RouterOS: The “MikroTrick” Exploit Chain
MikroTik RouterOS devices are also under attack, with CISA adding two critical vulnerabilities following reports from CERT Polska:
- CVE-2026-67277 (CVSS: 8.8): A missing authentication for a critical function vulnerability. This flaw in the btest service can lead to kernel memory disclosure and denial-of-service.
- CVE-2026-86060 (CVSS: 9.2): An improper neutralization of argument delimiters in a command vulnerability. Exploitation allows an attacker to alter the trusted RouterOS policy mask, achieving privilege escalation.
CERT Polska observed unknown threat actors exploiting these two flaws in a chain, dubbed “MikroTrick,” to gain unauthorized control over vulnerable MikroTik devices. This highlights the severe risk to network infrastructure if these devices remain unpatched.
Urgent Call to Action: Patching Deadlines
CISA has mandated strict patching deadlines for Federal Civilian Executive Branch (FCEB) agencies, emphasizing the urgency for all organizations:
- MikroTik RouterOS flaws (CVE-2026-67277, CVE-2026-86060): Patch by September 13, 2026.
- ConnectWise ScreenConnect flaw (CVE-2026-84869): Patch by September 14, 2026.
- JFrog Artifactory flaws (CVE-2026-42016, CVE-2026-42018): Patch by September 25, 2026.
These deadlines serve as a critical reminder for all entities utilizing these products to prioritize immediate updates. Proactive patching is the most effective defense against these actively exploited vulnerabilities, safeguarding systems from potential compromise and maintaining operational integrity.
For more details, visit our website.
Source: Link










Leave a comment