Skip to content
archivevulnerability · 11 Sep 2026 · 00:00 UTC

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

VULNKEVCVE-2026-42016source · JFR
KEVActive exploitation (KEV)
SHODANShodan: ~197,800 MikroTik exposed worldwide (07 Sep)

CISA KEV means this flaw has been seen exploited in real attacks — not predicted, observed. Treat it as urgent regardless of its score.

What to do
  • On CISA KEV — actively exploited. Patch immediately.
  • ~197,800 MikroTik are exposed worldwide — check your own version.

last 60 dispatches · spectrum

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected