Executive Summary
In September 2026, CISA added five critical vulnerabilities to its Known Exploited Vulnerabilities catalog following reports of active exploitation targeting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS systems. Attackers have been chaining multiple Artifactory flaws (CVE-2026-42016, CVE-2026-42018) with previously disclosed CVE-2026-82329 to bypass authentication, escalate privileges, and deploy Rust-based backdoors on self-hosted servers between August and September 2026. Additional exploitation includes ScreenConnect client abuse for malicious VBScript distribution and MikroTik router compromises through the MikroTrick exploit chain targeting authentication bypass vulnerabilities.
This incident highlights the accelerating trend of multi-vector exploitation campaigns where threat actors systematically chain vulnerabilities across enterprise infrastructure components to achieve comprehensive network compromise and establish persistent access.
Why This Matters Now
Organizations face increased risk from coordinated multi-vector attacks targeting critical infrastructure components, with attackers demonstrating sophisticated vulnerability chaining techniques that bypass traditional security controls and achieve rapid enterprise-wide compromise.
Attack Path Analysis
Attackers exploited multiple actively exploited vulnerabilities in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329), ConnectWise ScreenConnect (CVE-2026-84869), and MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060) to gain initial access through authentication bypass and privilege escalation. The attack chains enabled administrative control over vulnerable instances, deployment of persistent backdoors including Rust-based malware, and establishment of command channels through compromised infrastructure. Post-exploitation activities included creation of persistent administrator accounts, deployment of malicious Groovy plugins for code execution, and potential data exfiltration through compromised network infrastructure and remote access tools.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited authentication bypass vulnerabilities in JFrog Artifactory (CVE-2026-42018) to obtain internal anonymous-user tokens, and ConnectWise ScreenConnect client vulnerabilities (CVE-2026-84869) to execute files without authorization. MikroTik RouterOS devices were compromised via missing authentication flaws (CVE-2026-67277) allowing unauthenticated access to critical functions.
Related CVEs
CVE-2026-42016
CVSS 8.8An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to validation check of token signature/issuer but not token scope.
Affected Products:
JFrog Artifactory – < 7.90.7
Exploit Status:
exploited in the wildCVE-2026-42018
CVSS 7.5An improper authentication vulnerability in JFrog Artifactory that could return internal anonymous-user token to unauthenticated caller when anonymous access is disabled.
Affected Products:
JFrog Artifactory – < 7.90.7
Exploit Status:
exploited in the wildCVE-2026-84869
CVSS 9.9An improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect that allows file transfer and execution through active remote session without authorization.
Affected Products:
ConnectWise ScreenConnect – < 26.6.5
Exploit Status:
exploited in the wildCVE-2026-67277
CVSS 8.2A missing authentication for critical function vulnerability in MikroTik RouterOS that could allow kernel memory disclosure and denial-of-service in btest service.
Affected Products:
MikroTik RouterOS – < 7.16
Exploit Status:
exploited in the wildCVE-2026-86060
CVSS 9.8An improper neutralization of argument delimiters in command vulnerability in MikroTik RouterOS that allows attackers to change trusted RouterOS policy mask and achieve privilege escalation.
Affected Products:
MikroTik RouterOS – < 7.16
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Exploitation for Privilege Escalation
Create or Modify System Process: Windows Service
Command and Scripting Interpreter: Visual Basic
Server Software Component: Web Shell
Remote Services: VNC
Create Account: Local Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
CISA Zero Trust Maturity Model 2.0 – Vulnerability Management
Control ID: ID.RA-5
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
DORA – Identification
Control ID: Article 8
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Multi-vector exploitation targeting JFrog Artifactory, ScreenConnect, and RouterOS creates critical risks for IT infrastructure management, development pipelines, and remote access security systems.
Computer Software/Engineering
Artifactory vulnerabilities enable privilege escalation and backdoor deployment in software development environments, compromising CI/CD pipelines and source code repository integrity through authentication bypass.
Telecommunications
MikroTik RouterOS authentication bypass vulnerabilities allow network infrastructure hijacking without credentials, enabling kernel memory disclosure and privilege escalation in critical network routing equipment.
Financial Services
Remote access exploitation through ScreenConnect and network routing compromises threaten regulatory compliance under PCI-DSS and enable unauthorized access to sensitive financial systems and data.
Sources
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVhttps://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.htmlVerified
- CISA Adds Three Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalogVerified
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- ConnectWise ScreenConnect Security Bulletin 2026-09-08https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletinVerified
- Rogue ScreenConnect Clients Spread Four Types of Malwarehttps://www.huntress.com/blog/rogue-screenconnect-installationsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have reduced the attack's blast radius by constraining lateral movement between compromised infrastructure components and limiting east-west traffic flows. The segmented architecture could have contained the impact of multiple CVE exploitations across JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS systems.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial exploitation may still occur, CNSF would likely limit the scope of compromised systems by restricting network reachability and containing vulnerable services within isolated security zones.
Control: Zero Trust Segmentation
Mitigation: Zero Trust principles would likely constrain privilege escalation scope by limiting administrative access paths and reducing the ability to leverage compromised credentials across multiple infrastructure systems.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement by blocking unauthorized communication flows between compromised ScreenConnect instances and target systems, reducing the attack's ability to spread across network segments.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility controls would likely constrain command channel establishment by detecting anomalous communication patterns from compromised Artifactory instances and MikroTik devices, limiting sustained attacker coordination capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration by blocking unauthorized outbound transfers from compromised Artifactory instances and limiting covert channel establishment through compromised network infrastructure devices.
Despite successful exploitation, the overall impact would likely be contained to specific network segments rather than enterprise-wide compromise, limiting the scope of backdoor deployment and reducing supply chain contamination risks.
Impact at a Glance
Affected Business Functions
- Software Development and Build Pipelines
- Remote Access and IT Support
- Network Infrastructure Management
- Enterprise Security Operations
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of software artifacts, source code repositories, remote session data, network configuration details, and administrative credentials across enterprise environments. Confirmed deployment of backdoors and persistent administrator accounts in compromised Artifactory instances.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between compromised systems and limit blast radius of multi-vector exploitation
- • Deploy Inline IPS (Suricata) with updated signatures to detect and block known exploit patterns targeting CVE-2026-42016, CVE-2026-42018, CVE-2026-84869, CVE-2026-67277, and CVE-2026-86060
- • Enable Egress Security & Policy Enforcement with FQDN filtering to prevent unauthorized outbound communications and detect potential data exfiltration attempts from compromised Artifactory and ScreenConnect instances
- • Implement Multicloud Visibility & Control to detect anomalous interactions, repeated malformed requests, and suspicious automation patterns across hybrid infrastructure
- • Deploy East-West Traffic Security monitoring to identify lateral movement attempts and unauthorized service-to-service communications following initial compromise of network infrastructure devices



