CISA flags five actively exploited flaws in Artifactory, ScreenConnect and MikroTik gear

The U.S. cyber agency says criminals are already breaking into systems through bugs in three widely used products, and federal agencies must patch fast.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Aerial 16:9 editorial photograph of a multi-lane American interstate highway at dusk, large digital message signs mounted on overhead gantries displaying amber
Share

Key points

  • CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming each is being abused in live attacks.
  • The flaws affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
  • CVE-2026-42016, an authorisation flaw in Artifactory, is rated 8.1 out of 10 for severity.
  • Federal civilian agencies must patch on CISA's mandated timetable; private companies are strongly urged to follow.

CISA has told U.S. Federal agencies to patch five software flaws that criminals are already using to break into systems. The bugs sit inside three products a lot of businesses quietly rely on: JFrog Artifactory, which stores software packages for developers; ConnectWise ScreenConnect, a remote-support tool used by IT staff to log into other people's computers; and MikroTik RouterOS, the operating system running many small-business routers.

All five now sit on CISA's Known Exploited Vulnerabilities catalog, the agency's running list of bugs confirmed as exploited in the wild. Once a flaw lands there, federal civilian agencies have a hard deadline to install the vendor's fix. We covered the last batch of JFrog additions on 2 September, when CISA also picked up bugs in Sangoma, LiteLLM and SonicWall's remote-access appliances.

My read: ScreenConnect's presence on this list again is the part worth watching. Remote-access tools are catnip for ransomware crews, because one working exploit gives them a foot in the door of every downstream customer the IT provider looks after. We've seen this movie before.

What are the bugs, in plain English?

The headline flaw is CVE-2026-42016 in JFrog Artifactory, an incorrect-authorisation bug rated 8.1 out of 10. The software fails to properly check whether the person making a request is allowed to make it. That's an authorisation problem, not an authentication one: the system knows who you are, it just lets you do things you shouldn't be able to do.

The remaining four entries cover ScreenConnect and MikroTik RouterOS. The Hacker News, which first flagged CISA's update, notes the agency hasn't published deep technical detail on how each bug is being abused, only that exploitation is confirmed.

Product Role in a network Why it matters if broken
JFrog Artifactory Stores software builds and packages Attacker could tamper with code shipped to customers
ConnectWise ScreenConnect Remote IT support sessions Attacker gets hands-on control of endpoints
MikroTik RouterOS Runs routers and firewalls Attacker can reroute or spy on traffic

Who has to act, and by when?

Federal civilian agencies are legally required to patch KEV-listed bugs within the deadline CISA sets, usually three weeks. Private companies aren't bound by that rule, but insurers and auditors increasingly treat the KEV list as the minimum bar.

If you run any of these products, the job is straightforward. Check the vendor's security advisory, confirm which version you're on, and install the fixed release. For ScreenConnect in particular, also review recent remote-session logs for anything you didn't authorise.

Should you worry if you're not in IT?

Not directly. These are enterprise products, and the fix sits with the IT team at your employer or managed service provider. That said: if you get an unexpected pop-up saying someone wants to start a remote-support session on your work laptop, decline it and call your helpdesk on a number you already have. That single habit defeats a lot of ScreenConnect-based fraud.

Multi-factor authentication, the second login step where you approve a sign-in on your phone, wouldn't have blocked the Artifactory authorisation bug. The attacker is already past the login stage. It does help against the social-engineering side of ScreenConnect abuse, where a criminal phones an employee pretending to be IT. Turn it on.

© 2026 Threat Vectr