Cybersecurity

CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9

Published 2 min readBy NewUJ Editorial Desk

Updated factual errors corrected

CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
Photo: ConnectWise
0 0
XWhatsAppTelegramLinkedIn

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog in entries dated September 10 and 11, 2026, citing evidence of active exploitation in each case. Two of the flaws sit in JFrog Artifactory, one in ConnectWise ScreenConnect and two in MikroTik RouterOS.

The most severe is CVE-2026-84869 in ScreenConnect, which the National Vulnerability Database rates 9.9 on the CVSS 3.1 scale. The KEV entry describes improper privilege management combined with a missing authorization check, allowing file transfer and code execution through an active remote session without authorization. ConnectWise places the condition in the ScreenConnect client rather than the server and fixed it in version 26.6.5. CISA gave U.S. federal civilian agencies until September 14, 2026 — the shortest window in this batch.

The deadlines were staggered rather than uniform. The two MikroTik RouterOS bugs were due September 13: CVE-2026-67277, a missing-authentication flaw in the btest service that can disclose kernel memory or cause a denial of service, and CVE-2026-86060, an argument-handling flaw in the SSH login path that lets an attacker change the trusted policy mask and escalate privileges. NVD scores both on two scales that do not agree: CVE-2026-67277 is 8.2 under CVSS 3.1 and 8.8 under CVSS 4.0, while CVE-2026-86060 is 9.8 under CVSS 3.1 and 9.2 under CVSS 4.0. CERT Polska, the Polish national response team, said it had observed attacks against RouterOS devices reachable from the internet. The two Artifactory entries carried a September 25 deadline: CVE-2026-42016 (CVSS 8.1), privilege escalation through a token-scope bypass, and CVE-2026-42018 (CVSS 7.5), which can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled.

These are infrastructure tools, not desktop apps. Artifactory stores the build artifacts that feed software supply chains; ScreenConnect is the remote-access console IT teams and managed service providers use to reach customer machines; MikroTik gear sits at the network edge. The Hacker News reported on September 12, 2026 that Google-owned Wiz had observed attackers chaining the two new Artifactory flaws with CVE-2026-82329 — a bug CISA added to KEV on September 2 with a September 5 deadline — between August 15 and September 8 to seize administrative control of vulnerable instances, then create persistent administrator accounts, deploy malicious Groovy plugins and install Rust-based backdoors. Huntress separately documented three unrelated ScreenConnect incidents in which attackers pushed a malicious VBScript payload to newly connected systems. That is the operational point: an organization that patches without auditing accounts may leave the intruder's access intact.

What remains unknown: CISA has not published how many organizations, servers or devices were actually compromised, and the available reporting describes only unknown threat actors, with no attribution. A sourced exploitation window exists solely for the Artifactory chain; the start dates of the ScreenConnect and RouterOS activity have not been disclosed. KEV deadlines legally bind federal civilian agencies alone, but CISA urges every organization to treat the catalog as a patch-priority list.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.