Threat Intelligence

CISA Flags Five Actively Exploited Flaws in Artifactory, ScreenConnect and RouterOS

The Hacker News · 13 Sept 2026
Key Takeaway If your business uses JFrog Artifactory, ConnectWise ScreenConnect, or MikroTik RouterOS, apply the latest vendor patches immediately rather than waiting, since these flaws are already being exploited in real attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog after confirming they are being actively exploited. The affected products are JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, all widely used in business IT environments.

Attackers have been chaining Artifactory vulnerabilities together to bypass authentication, gain administrator control of self-hosted servers, and install persistent backdoors, according to research from Wiz. Separately, a ScreenConnect flaw has been abused to push malicious script files to newly connected systems, as documented in incidents reported by Huntress. Two additional flaws in MikroTik RouterOS, dubbed 'MikroTrick' by CERT Polska, allow attackers to take control of vulnerable devices without needing to authenticate at all.

CISA has directed U.S. federal agencies to patch the RouterOS flaws by 13 September 2026, the ScreenConnect flaw by 14 September 2026, and the Artifactory flaws by 25 September 2026. While these deadlines apply only to federal agencies, the active exploitation means any organisation running these products faces real risk if left unpatched.

CISA KEV vulnerability management ScreenConnect RouterOS

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.