CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Summary
CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. These additions are due to reports of these flaws being actively exploited in the wild by threat actors.
IFF Assessment
The addition of actively exploited vulnerabilities to CISA's KEV catalog indicates that these flaws are being used by attackers, posing a direct threat to organizations and their data.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 25, 2026. Known ransomware use: Unknown.
Defender Context
Organizations utilizing JFrog Artifactory, ConnectWise ScreenConnect, or MikroTik RouterOS should prioritize patching these identified vulnerabilities to mitigate the risk of exploitation. Monitoring for related indicators of compromise is also crucial, as these flaws are known to be actively exploited.