Cybersecurity & Protection

CISA Adds Active Exploits in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to Known Exploited Vulnerabilities Catalog

The United States Cybersecurity and Infrastructure Security Agency (CISA) has expanded its authoritative Known Exploited Vulnerabilities (KEV) catalog to include five critical security flaws affecting enterprise software and networking infrastructure. The latest additions target widely deployed platforms developed by JFrog, ConnectWise, and MikroTik, underscoring an alarming escalation in automated threat activity and multi-stage exploit chaining by cybercriminals and advanced persistent threat (APT) groups alike.

According to federal mandates, civilian government agencies must remediate these specific vulnerabilities within strict compliance windows, highlighting the immediate and pressing danger these security holes pose to enterprise networks worldwide. Cybersecurity researchers from prominent threat intelligence firms, including Google-owned Wiz, Huntress, and CERT Polska, have detailed aggressive in-the-wild exploitation campaigns targeting these exact pathways. The tactics employed by threat actors range from stealthy administrative hijacking and persistent backdoor deployments to unauthorized file transfers and remote code execution.

Anatomy of the Exploitation Campaigns

The inclusion of these vulnerabilities in CISA’s KEV catalog is the direct result of coordinated telemetry from private-sector threat hunters and global incident responders. The attacks leverage sophisticated methodologies designed to bypass standard perimeter defenses, elevate local or remote privileges, and establish long-term persistence within targeted environments.

In the case of JFrog Artifactory, threat actors have been observed executing complex exploit chains between August 15 and September 8, 2026. Attackers leverage multiple Artifactory flaws alongside CVE-2026-82329—a critical vulnerability boasting a maximum CVSS score of 9.8, which was added to the KEV catalog earlier in the month. By chaining these security weaknesses together, unauthorized external parties can completely bypass authentication mechanisms.

Cloud security firm Wiz noted that once attackers acquire initial access, they swiftly escalate privileges to seize full administrative control over self-hosted Artifactory servers. Post-exploitation activities identified in these incidents include the automated creation of rogue administrator accounts, the deployment of malicious Groovy plugins engineered for unauthorized code execution, and the installation of custom Rust-based backdoors. These backdoors ensure that even if basic entry points are patched, the malicious actors retain persistent, covert access to the underlying infrastructure.

Parallel threats have materialized around ConnectWise ScreenConnect. Exploitation of CVE-2026-84869 has been tied directly to distinct campaigns uncovered by Huntress researchers. In these instances, malicious actors abused legitimate mechanics within the ScreenConnect client framework to propagate a malicious Visual Basic Script (VBScript) payload directly to newly connected host systems.

ConnectWise characterized this issue as a functional condition within the client software rather than a server-side vulnerability. Under specific operational conditions, the flaw facilitates unauthorized file transfers and direct execution on the host client system, bypassing host confirmation even during elevated execution actions. Huntress and ConnectWise have both strongly urged system administrators to upgrade instances immediately to ScreenConnect version 26.6.5 to mitigate the risk of rogue client manipulation.

Meanwhile, networking infrastructure has faced intense assault via a dual-vector exploit chain dubbed "MikroTrick." CERT Polska revealed that unidentified threat actors successfully targeted MikroTik RouterOS instances, exploiting CVE-2026-67277 and CVE-2026-86060 without requiring prior authentication. These vulnerabilities allow attackers to bypass security perimeters entirely, granting them administrative command and control over vulnerable network routers, which can subsequently be utilized to pivot deeper into corporate or municipal internal networks.

Chronology of Events and CISA Mandates

The rapid pace at which these security flaws have transitioned from discovery to active weaponization and official cataloging demonstrates the compressed window of modern cyber conflict. A detailed timeline outlines the progression of these critical events:

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
  • August 15, 2026: Threat actors begin initiating coordinated, multi-stage exploitation campaigns targeting self-hosted JFrog Artifactory servers using chained vulnerabilities.
  • Late August 2026: Independent security researchers identify rogue ScreenConnect client installations actively distributing VBScript payloads to connected workstations.
  • Early September 2026: CERT Polska identifies and publicly reports the "MikroTrick" exploit campaign, noting widespread unauthenticated takeovers of MikroTik RouterOS devices.
  • September 8, 2026: ConnectWise issues formal security bulletins and patches regarding the ScreenConnect client file-transfer vulnerability, prompting immediate adoption of version 26.6.5.
  • September 10–11, 2026: CISA officially incorporates the MikroTik and ScreenConnect vulnerabilities into its Known Exploited Vulnerabilities catalog.
  • September 12, 2026: CISA updates and consolidates catalog entries, setting hard compliance deadlines for Federal Civilian Executive Branch (FCEB) agencies.

To mitigate systemic national security risks, CISA has enforced stringent federal remediation deadlines under Binding Operational Directive (BOD) 22-01. FCEB agencies are legally required to apply security patches or implement authorized mitigations according to the following schedule:

  • MikroTik RouterOS vulnerabilities (CVE-2026-67277 and CVE-2026-86060): Remediation deadline set for September 13, 2026.
  • ConnectWise ScreenConnect vulnerability (CVE-2026-84869): Remediation deadline set for September 14, 2026.
  • JFrog Artifactory vulnerabilities: Remediation deadline set for September 25, 2026.

Industry Analysis and Official Responses

Software vendors and cybersecurity organizations have responded to the wave of active exploitation with urgent advisories and patches. The speed and complexity of the observed attacks have prompted security analysts to re-evaluate the traditional boundaries of enterprise supply chain security.

JFrog Artifactory and ConnectWise have worked closely with incident response firms to issue comprehensive remediation guidelines. ConnectWise emphasized that the ScreenConnect flaw does not compromise centralized server architecture, but rather exposes individual client endpoints if active remote sessions are manipulated maliciously. The introduction of unauthorized file transfer pathways through elevated execution privileges represents a severe deviation from expected operational parameters, making client-side updates mandatory for all managed service providers (MSPs) and enterprise IT teams utilizing the software.

Similarly, the exploitation of MikroTik RouterOS highlights the ongoing vulnerabilities inherent in edge networking equipment. Because routers and gateways sit at the absolute perimeter of enterprise environments, unauthenticated remote code execution flaws present a catastrophic risk profile. Threat actors who capture these devices can intercept traffic, establish persistent tunnels, and evade detection by blending into legitimate administrative traffic streams.

Security analysts at Wiz and Huntress have stressed that standard vulnerability management—relying solely on CVSS scoring—is no longer sufficient for prioritizing defense operations. The practice of exploit chaining, wherein moderate or critical flaws are combined to achieve total system compromise, requires security teams to adopt a contextual, threat-informed defense strategy. Monitoring for abnormal post-exploitation indicators, such as the unexpected spawning of Rust-based binaries, rogue administrator account creation, or anomalous Groovy plugin deployments, remains critical for catching advanced intrusions in progress.

Broader Impact and Implications for Enterprise Security

The inclusion of these five vulnerabilities into CISA’s KEV catalog serves as a broader bellwether for the state of enterprise cybersecurity. As software ecosystems grow increasingly interconnected, developers face immense pressure to secure not only primary application code but also auxiliary plugins, client-side libraries, and edge-device firmware.

When enterprise-grade repositories like JFrog Artifactory are compromised, the integrity of an organization’s entire software development lifecycle (SDLC) is thrown into question. Attackers who gain administrative control over artifact repositories can potentially inject malicious code into software builds before they are compiled and distributed to end-users, transforming trusted development infrastructure into a vector for downstream supply chain attacks.

Furthermore, the abuse of remote monitoring and management (RMM) tools like ConnectWise ScreenConnect illustrates the ongoing "living off the trusted systems" phenomenon. Cybercriminals increasingly prefer to subvert legitimate administrative utilities rather than deploy custom malware, allowing their malicious activities to blend seamlessly with normal business operations.

Organizations outside the federal sector are strongly encouraged to treat CISA’s KEV catalog benchmarks as mandatory guidelines for internal vulnerability management. Private enterprises, critical infrastructure providers, and educational institutions are urged to audit their networks for affected versions of MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory immediately. Implementing robust endpoint detection and response (EDR) solutions, enforcing strict multi-factor authentication (MFA) across all administrative portals, and maintaining rigorous log-monitoring practices remain the most effective defenses against the sophisticated, multi-stage exploitation techniques currently dominating the threat landscape.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Lock It Soft
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.