CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Executive Summary
CISA has added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The flaws affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. One example, CVE‑2026‑42016, scores 8.1 on CVSS and involves incorrect authorization, with active exploitation reported in the wild.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-12T15:54:45+00:00 - Category: threat-intel
Original Description: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization
"You get peace of mind not by thinking about it or imagining it, but by quietening and relaxing the restless mind."
— Remez Sasson