LIVE · cybersecurity feed
Live wire
CVE-2026-42016high

CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEV

The Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities catalog. These flaws affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, and have been observed being actively exploited in the wild. One of the listed vulnerabilities, CVE-2026-42016, has a CVSS score of 8.1 and involves an incorrect authorization issue.

zeroday.news ·

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog, adding five new flaws that have been observed under active exploitation. These vulnerabilities impact products from JFrog, ConnectWise, and MikroTik, specifically affecting Artifactory, ScreenConnect, and RouterOS platforms. The inclusion in the KEV catalog mandates that U.S. federal agencies remediate these issues within a specified timeframe due to their proven exploitation in real-world attacks.

Among the newly cataloged vulnerabilities, one identified as CVE-2026-42016 stands out with a CVSS score of 8.1. This particular flaw is characterized as an incorrect authorization issue. Incorrect authorization vulnerabilities typically arise when an application fails to properly verify that a user or process has the necessary permissions to access a resource or perform an action. This can allow an attacker to bypass security controls and gain unauthorized access to sensitive data or functionality.

JFrog Artifactory is a universal repository manager widely used in software development for managing binary artifacts and dependencies across the software supply chain. ConnectWise ScreenConnect is a remote desktop access and support solution, commonly employed by IT professionals for managing client systems. MikroTik RouterOS is the operating system for MikroTik's line of routers and wireless ISP systems, providing network routing, firewall, and VPN capabilities. The diverse nature of these affected products suggests that attackers are targeting a broad spectrum of infrastructure components, from development pipelines to remote access tools and network edge devices.

Exploitation of vulnerabilities in products like Artifactory could lead to supply chain attacks, where malicious code is injected into legitimate software components. For ScreenConnect, successful exploitation could grant attackers remote control over systems, enabling data exfiltration, lateral movement, or the deployment of further malware. In the case of RouterOS, compromise could lead to network disruption, unauthorized access to internal networks, or the establishment of persistent backdoors for espionage or further attacks.

Mitigation for these types of vulnerabilities generally involves applying vendor-supplied patches as soon as they become available. For incorrect authorization flaws, developers often need to review and strengthen access control mechanisms, ensuring that all requests are properly authenticated and authorized against defined policies. Organizations are also advised to implement robust network segmentation, principle of least privilege, and continuous monitoring to detect and respond to suspicious activity that might indicate exploitation. Regular security audits and penetration testing can help identify and address such weaknesses proactively.

The continuous addition of vulnerabilities to CISA's KEV catalog underscores the persistent threat posed by actively exploited flaws and the critical importance of timely patching and robust vulnerability management. This ongoing effort by CISA aims to provide federal agencies and, by extension, the broader cybersecurity community, with actionable intelligence to prioritize remediation efforts against the most pressing threats. The focus on widely used enterprise and infrastructure software highlights the need for all organizations to maintain vigilance and proactive security postures to defend against sophisticated and opportunistic attackers.

vulnerabilities in this storyCVE-2026-42016
cisakevvulnerabilitiesexploitationartifactory
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s