CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

September 12, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations using JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS
Incident: Active exploitation of five critical vulnerabilities across three software platforms.
Impact: Full administrative takeover, remote code execution, and persistent backdoor installation.
Attacker: Unidentified threat actors
Analysis: Threat actors are utilizing sophisticated vulnerability chains to bypass authentication and escalate privileges. In Artifactory instances, this results in the deployment of Rust-based backdoors, while ScreenConnect is being abused to push malicious VBScript payloads. Additionally, the ‘MikroTrick’ chain allows unauthorized seizure of MikroTik RouterOS devices.
Recommendations: Immediately update JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to the latest patched versions.; Audit Artifactory instances for unauthorized administrator accounts or suspicious Groovy plugins.; Review network logs for anomalous activity targeting the btest service on MikroTik devices.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *