The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include five critical flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.

  • CISA has officially added five new vulnerabilities to its KEV catalog.
  • Targeted systems include JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS.
  • These flaws are currently being actively exploited in real-world cyberattacks.

The Cybersecurity and Infrastructure Security Agency (CISA) has taken a decisive step to bolster national defense by adding five security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities are not merely theoretical risks; they are being actively leveraged by threat actors to compromise systems in the wild.

The newly added flaws impact widely used enterprise tools, including JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Notably, CVE-2026-42016, which carries a high CVSS score of 8.1, involves an incorrect authorization flaw that could allow attackers to bypass security protocols and gain unauthorized access to sensitive environments.

Why This Matters

BozokMedia analysis shows that the inclusion of these specific tools in the KEV catalog highlights a growing trend in Supply Chain Attacks. When software used for deployment (Artifactory) or remote management (ScreenConnect) is compromised, the blast radius extends to every organization relying on those services, potentially leading to massive data breaches and lateral movement within networks.

The transition from theoretical vulnerability to active exploitation marks the highest level of urgency for enterprise patch management.

Historically, vulnerabilities in networking hardware like MikroTik RouterOS have been a goldmine for botnet operators and state-sponsored actors, as compromising a router provides a foothold into an entire organizational architecture. Organizations are urged to prioritize these updates to mitigate immediate risks.

Did You Know?: The KEV catalog is specifically designed to help organizations prioritize their patching efforts based on actual threat intelligence rather than just severity scores.

Frequently Asked Questions

1. What does it mean when a vulnerability is added to the KEV catalog?
It means CISA has confirmed that hackers are actively using this flaw to attack real organizations.

2. How can I protect my organization?
The most effective defense is to immediately apply the security patches provided by the respective vendors (JFrog, ConnectWise, and MikroTik).