Back to advisories

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

CISA added 5 actively exploited vulnerabilities to the KEV catalog affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Attackers are chaining these flaws to gain admin access, deploy backdoors, and distribute malware. Federal agencies must patch by specific deadlines; all organizations should treat as mandatory.

CRITICALAdvisorySep 14, 2026
Action required
Immediately inventory all instances of Artifactory, ScreenConnect, and RouterOS in your environment. Prioritize patching these three products to latest versions. Run threat hunts for lateral movement, suspicious admin account creation, and backdoor artifacts on affected systems.
Affected products
JFrog ArtifactoryConnectWise ScreenConnectMikroTik RouterOSJFrogConnectWise