CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
2026-09-13T01:23:59Z•0dbaee4e2a4e0f50c2020984db0b5add2dbcff1c73e9350c3ac08debaad2f752
CVE-2026-20079CVE-2026-42016CVE-2026-85706AI-assisted-attacksAndroid-malwareCISA-KEVCheck-PointCisco-FMCConnectWise-ScreenConnectGitLabJFrog-ArtifactoryLLM-securityMFA-bypassMikroTik-RouterOSPaperCutactive-exploitationarbitrary-file-readauthentication-bypasscredential-theftcritical-vulnerabilitiescyber-espionageinfostealersmisconfigurationpath-traversalransomwareremote-code-executionsupply-chain-security
What happened
The feed highlights widespread active exploitation and high-impact security incidents, including CISA KEV additions affecting JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, Cisco FMC, Citrix, and Fortinet. Major themes include unauthenticated remote code execution, authentication bypass, arbitrary file reads, supply-chain compromise, ransomware deployment, AI-assisted exploitation, infostealer theft of replayable AI tokens, Android banking malware, and exposed administrative credentials. Several reports describe exploitation in the wild, including attacks against GitLab, Art
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0dbaee4e2a4e0f50c2020984db0b5add2dbcff1c73e9350c3ac08debaad2f752
- Enrichment time
- 2026-09-13T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.