Summary
- CISA has added five vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog.
- All five flaws are confirmed as actively exploited in the wild, not merely theoretical risks.
- CVE-2026-42016, an incorrect authorisation flaw in one of the affected products, carries a CVSS score of 8.1.
- Federal agencies in the US are bound by KEV listing directives; Australian organisations and private-sector security teams should treat these as high-priority remediation items.
- Corroborating detail beyond the primary source is not available at time of publication.
What Has Been Listed
The US Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog with five newly confirmed flaws spanning three product families: JFrog Artifactory, a widely used software artifact repository; ConnectWise ScreenConnect, a remote access and support platform prevalent in managed service provider environments; and MikroTik RouterOS, which underpins a significant share of edge networking infrastructure globally.
The Vulnerabilities
The source material identifies CVE-2026-42016 as one of the five additions, carrying a CVSS score of 8.1 and classified as an incorrect authorisation vulnerability. Full details of the remaining four CVEs were not included in the available source material, so organisations should consult the CISA KEV catalog directly for the complete listing and associated remediation guidance.
Why the KEV Listing Matters Beyond Federal Compliance
CISA’s KEV catalog was designed primarily to drive remediation within US federal civilian agencies, but its practical value extends well beyond that boundary. A KEV listing confirms that threat actors are actively weaponising a flaw in real environments — not just in proof-of-concept research. For security leaders in the private sector, and particularly for those operating in Australia where guidance from the Australian Signals Directorate mirrors similar risk-prioritisation frameworks, a KEV entry is a reliable indicator that the vulnerability warrants immediate attention.
The Risk Profile of These Products
The three affected product families represent meaningful exposure points for many organisations. Artifactory is embedded in software development pipelines and often holds credentials, build artefacts, and dependencies — making it an attractive target for supply chain intrusion. ScreenConnect is extensively deployed by managed service providers and IT support teams, and a compromised instance can provide an adversary with authenticated remote access to a large number of downstream environments simultaneously. MikroTik RouterOS devices are common in small-to-medium enterprise networks and have previously been exploited at scale to build botnet infrastructure. The combination of these three products in a single advisory batch suggests broad targeting across different attack surfaces.
Limitations of Available Information
The source material does not attribute the active exploitation to specific threat actors or campaigns, nor does it specify the attack vectors beyond the vulnerability classifications. The nature of the remaining four CVEs — including their CVSS scores, affected versions, and patch availability — is not detailed in the available source material. Organisations should not wait for fuller public disclosure before beginning assessment; the KEV listing itself is sufficient grounds to treat these as urgent.
Why it matters
For CISOs, this catalog update touches three distinct risk domains at once: the software supply chain via Artifactory, remote access infrastructure via ScreenConnect, and network edge devices via RouterOS. Each of these surfaces has historically been leveraged for lateral movement, credential harvesting, and persistent access. The fact that exploitation is confirmed — not hypothetical — means the window for remediation without incident has narrowed. Organisations running managed service provider models or supporting multiple client environments through ScreenConnect face compounded exposure if a single instance is compromised. The RouterOS entries are a reminder that network devices frequently fall outside normal patch management cycles and deserve specific attention.
What to do now
- Consult the CISA KEV catalog directly to retrieve the full list of five CVEs, affected product versions, and any associated remediation deadlines.
- Audit your environment for instances of JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS and confirm which versions are deployed.
- Apply vendor-supplied patches or mitigations for all five listed vulnerabilities as a priority, in line with your organisation’s vulnerability management SLA for actively exploited flaws.
- If you operate ScreenConnect in a managed service provider context, assess whether any downstream client environments may be exposed through shared instances.
- Review MikroTik RouterOS devices for signs of compromise or unauthorised configuration changes, given historical exploitation of these devices for botnet activity.
