Published Saturday, September 12, 2026 at 11:16 AM PT

<strong>CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, RouterOS Flaws to KEV</strong>

BLUF: CISA has added 5 actively exploited vulnerabilities affecting Artifactory, ScreenConnect, and RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. Organizations running these products should assume exploitation is underway and patch immediately.


DETAILS

  • CISA formally added 5 flaws to the KEV catalog, confirming active exploitation in the wild
  • Affected products: JFrog Artifactory, ConnectWise ScreenConnect, and Mikrotik RouterOS
  • Attack activity is ongoing — these are not theoretical risks
  • Flaws span remote code execution and authentication bypass categories
  • Multiple attack groups are actively scanning for and exploiting these flaws

IMPACT

  • Artifactory users: Risk of credential theft, artifact tampering, supply-chain compromise if repositories are internet-exposed
  • ScreenConnect deployments: Remote access tools are high-value targets; full environment compromise likely if exploited
  • RouterOS instances: Perimeter devices and remote management systems are at immediate risk of takeover
  • Scope: Any instance accessible to attackers or on networks where lateral movement is possible

RECOMMENDED ACTIONS

  1. Immediate: Query your asset inventory for Artifactory, ScreenConnect, RouterOS instances. Identify public-facing, internet-accessible, or edge-network deployments.
  2. Within 24 hours: Apply CISA-recommended mitigations or patches. Check vendor security advisories for version-specific guidance.
  3. Monitor: Watch for unauthorized access, credential leaks, or unusual artifact/configuration changes in Artifactory; inspect ScreenConnect session logs for anomalous RDP/SSH tunneling; review RouterOS firewall logs for unexpected management access.
  4. Incident response: Test your ability to isolate and forensically preserve these systems if compromise is suspected.

SOURCES

  • CISA Known Exploited Vulnerabilities (KEV) catalog
  • The Hacker News reporting

Status: Active exploitation confirmed by CISA. Specific CVE numbers and technical details pending full KEV release.


Recent high-severity events at publish time:

Recent high-severity events