CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

2026-09-13T01:23:59Z•0dbaee4e2a4e0f50c2020984db0b5add2dbcff1c73e9350c3ac08debaad2f752
CVE-2026-20079CVE-2026-42016CVE-2026-85706AI-assisted-attacksAndroid-malwareCISA-KEVCheck-PointCisco-FMCConnectWise-ScreenConnectGitLabJFrog-ArtifactoryLLM-securityMFA-bypassMikroTik-RouterOSPaperCutactive-exploitationarbitrary-file-readauthentication-bypasscredential-theftcritical-vulnerabilitiescyber-espionageinfostealersmisconfigurationpath-traversalransomwareremote-code-executionsupply-chain-security

What happened

The feed highlights widespread active exploitation and high-impact security incidents, including CISA KEV additions affecting JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, Cisco FMC, Citrix, and Fortinet. Major themes include unauthenticated remote code execution, authentication bypass, arbitrary file reads, supply-chain compromise, ransomware deployment, AI-assisted exploitation, infostealer theft of replayable AI tokens, Android banking malware, and exposed administrative credentials. Several reports describe exploitation in the wild, including attacks against GitLab, Art

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0dbaee4e2a4e0f50c2020984db0b5add2dbcff1c73e9350c3ac08debaad2f752
Enrichment time
2026-09-13T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.