Back to News
Cybersecurity

CISA Flags New Vulnerabilities in Artifactory, ScreenConnect, and RouterOS as Actively Exploited

CISA has added five critical vulnerabilities to its KEV catalog, highlighting urgent security concerns for businesses using affected software.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include five critical security flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. The inclusion of these vulnerabilities, notably CVE-2026-42016, which has a CVSS score of 8.1 due to an incorrect authorization issue, underscores the urgency for organizations utilizing these platforms to take immediate action. Reports of active exploitation in the wild have prompted CISA to prioritize these vulnerabilities, indicating a significant risk landscape for businesses relying on these technologies.

For organizations using JFrog Artifactory, ConnectWise ScreenConnect, or MikroTik RouterOS, the announcement serves as a critical reminder of the importance of robust cybersecurity measures. Businesses are urged to review their systems, apply necessary patches, and enhance their security protocols to mitigate potential exploitations. This situation highlights the broader implications for cybersecurity, emphasizing the need for continuous monitoring and proactive vulnerability management, especially as adversaries increasingly target known weaknesses in widely used software. As cyber threats evolve, understanding and addressing these vulnerabilities is essential for maintaining organizational resilience and safeguarding sensitive data.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html)*