CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog in entries dated September 10 and 11, 2026, citing evidence of active exploitation in each case. Two of the flaws sit in JFrog Artifactory, one in ConnectWise ScreenConnect and two in MikroTik RouterOS.
The most severe is CVE-2026-84869 in ScreenConnect, which the National Vulnerability Database rates 9.9 on the CVSS 3.1 scale. The KEV entry describes improper privilege management combined with a missing authorization check, allowing file transfer and code execution through an active remote session without authorization. ConnectWise places the condition in the ScreenConnect client rather than the server and fixed it in version 26.6.5. CISA gave U.S. federal civilian agencies until September 14, 2026 — the shortest window in this batch.
The deadlines were staggered rather than uniform. The two MikroTik RouterOS bugs were due September 13: CVE-2026-67277, a missing-authentication flaw in the btest service that can disclose kernel memory or cause a denial of service, and CVE-2026-86060, an argument-handling flaw in the SSH login path that lets an attacker change the trusted policy mask and escalate privileges. NVD scores both on two scales that do not agree: CVE-2026-67277 is 8.2 under CVSS 3.1 and 8.8 under CVSS 4.0, while CVE-2026-86060 is 9.8 under CVSS 3.1 and 9.2 under CVSS 4.0. CERT Polska, the Polish national response team, said it had observed attacks against RouterOS devices reachable from the internet. The two Artifactory entries carried a September 25 deadline: CVE-2026-42016 (CVSS 8.1), privilege escalation through a token-scope bypass, and CVE-2026-42018 (CVSS 7.5), which can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled.
These are infrastructure tools, not desktop apps. Artifactory stores the build artifacts that feed software supply chains; ScreenConnect is the remote-access console IT teams and managed service providers use to reach customer machines; MikroTik gear sits at the network edge. The Hacker News reported on September 12, 2026 that Google-owned Wiz had observed attackers chaining the two new Artifactory flaws with CVE-2026-82329 — a bug CISA added to KEV on September 2 with a September 5 deadline — between August 15 and September 8 to seize administrative control of vulnerable instances, then create persistent administrator accounts, deploy malicious Groovy plugins and install Rust-based backdoors. Huntress separately documented three unrelated ScreenConnect incidents in which attackers pushed a malicious VBScript payload to newly connected systems. That is the operational point: an organization that patches without auditing accounts may leave the intruder's access intact.
What remains unknown: CISA has not published how many organizations, servers or devices were actually compromised, and the available reporting describes only unknown threat actors, with no attribution. A sourced exploitation window exists solely for the Artifactory chain; the start dates of the ScreenConnect and RouterOS activity have not been disclosed. KEV deadlines legally bind federal civilian agencies alone, but CISA urges every organization to treat the catalog as a patch-priority list.
Sources
- CISA Known Exploited Vulnerabilities CatalogPrimary source
- NIST National Vulnerability Database — CVE-2026-84869Primary source
- CERT Polska — Vulnerabilities in MikroTik RouterOS softwarePrimary source
- The Hacker News — CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVSecondary
Related
Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22
Trending now
- Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
- Zverev Beats Shelton in 4 Sets for First US Open Title
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
- Treasury Yield Tops 5.014%, Highest Since 2023, Then Retreats
- US Diesel Sets Record $6.23 a Gallon, AAA Figures Show
Comments
No comments yet. Be the first.