What happened and why it matters
CISA just put five actively exploited flaws into its Known Exploited Vulnerabilities (KEV) catalog, and the clock is already ticking for federal agencies.
Vulnerabilities at a glance
- CVE-2026-42016 (JFrog Artifactory) – CVSS 8.1
- CVE-2026-42018 (JFrog Artifactory) – CVSS 7.5
- CVE-2026-84869 (MikroTik RouterOS) – CVSS 9.9
- CVE-2026-67277 (MikroTik RouterOS) – CVSS 8.8
- CVE-2026-86060 (MikroTik RouterOS) – CVSS 9.2
Earlier this month CISA also added CVE-2026-82329 (ConnectWise ScreenConnect) with a CVSS of 9.8.
Technical details
ConnectWise says the ScreenConnect client flaw can let an attacker move files and run them during an active remote session, even if the host never approved the action.
Huntress saw three separate incidents where threat actors abused ScreenConnect to drop a malicious Visual Basic Script payload. Their recommendation? Upgrade to ScreenConnect 26.6.5 right away.
In the MikroTik world, CERT Polska observed exploitation of two RouterOS flaws by unknown actors. They dubbed the attack chain “MikroTrick”.
Who needs to act
Any federal civilian agency that runs these products must patch them by the dates CISA set:
- RouterOS – by 2026‑09‑13
- ScreenConnect – by 2026‑09‑14
- Artifactory – by 2026‑09‑25
What you can do now
- Apply the vendor‑supplied patches or updates immediately.
- Verify that ScreenConnect is running version 26.6.5 or later.
- Audit Artifactory instances for any unexpected admin accounts or unknown plugins.
- Monitor network traffic for signs of the “MikroTrick” exploit chain.
- Review CISA’s KEV guidance for any additional remediation steps.
