Top Highlights
- Hackers are chaining vulnerabilities in JFrog Artifactory to escalate privileges, bypass authentication, and deploy backdoors, leading to potential full control of compromised servers.
- Exploitation of MikroTik RouterOS flaws can result in device takeover and denial-of-service, with threat actors exploiting missing authentication and privilege escalation vulnerabilities.
- ConnectWise ScreenConnect’s flaw allows unauthorized file transfers and execution during remote sessions, enabling malicious payload deployment and remote system compromise.
Threat, Attack Techniques, and Targets
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog. These flaws affect JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Attackers are actively exploiting these vulnerabilities in the wild.
For Artifactory, attackers are chaining two bugs (CVE-2026-42016 and CVE-2026-42018). They use these to bypass authentication and take control of servers. Attackers can escalate privileges and create backdoors to maintain access.
In ScreenConnect, the flaw (CVE-2026-84869) allows attackers to transfer and run malicious files during active remote sessions. They can execute code without permission or host confirmation.
For MikroTik RouterOS, two flaws (CVE-2026-67277 and CVE-2026-86060) allow attackers to control devices without needing authentication. They can cause memory leaks, trigger denial-of-service, or escalate privileges.
In some cases, attackers combine these vulnerabilities to increase their chances of success. They target self-hosted servers, remote systems, and network devices.
Impact, Security Implications, and Remediation Guidance
Exploiting these vulnerabilities can cause serious issues. Attackers can gain unauthorized access, take control of devices, and deploy backdoors or malware. They can also disrupt services by causing device crashes or memory issues.
The vulnerabilities that involve privilege escalation and remote code execution pose high risks. Attackers may create persistent administrator accounts or install backdoors for ongoing access.
Organizations should apply patches or updates to affected products. According to CISA, FCEB agencies must fix the MikroTik RouterOS flaws by September 13, ScreenConnect by September 14, and Artifactory by September 25, 2026.
Since specific remediation details are not provided in the brief, organizations should consult the vendor or official security advisories. It is important to patch affected systems quickly to reduce the risk of exploitation.
Expand Your Tech Knowledge
Explore the future of technology with our detailed insights on Artificial Intelligence.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
