{"id":1687,"date":"2026-09-16T15:07:59","date_gmt":"2026-09-16T09:37:59","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1687"},"modified":"2026-09-21T12:14:32","modified_gmt":"2026-09-21T06:44:32","slug":"cisa-kev-artifactory-screenconnect-routeros","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/","title":{"rendered":"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities"},"content":{"rendered":"<p>CISA recently added five actively exploited Artifactory, ScreenConnect and RouterOS vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The flaws affect JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS.<\/p>\n<p>However, the five flaws expose different security boundaries. The Artifactory vulnerabilities can be chained from unauthenticated access toward administrative control. The ScreenConnect flaw affects file transfer and execution during active remote sessions. Meanwhile, the RouterOS vulnerabilities affect SSH privilege handling and the bandwidth-test service.<\/p>\n<p>For security teams, this is not one patching problem. Each vulnerability requires remediation and investigation at its respective application, endpoint or network layer.<\/p>\n<h2>Five Artifactory, ScreenConnect and RouterOS Vulnerabilities in CISA KEV<\/h2>\n<p>The vulnerabilities affect software repositories, remote-support endpoints and network infrastructure.<\/p>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"6\" aria-colcount=\"6\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Product<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Vulnerability<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVSS<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Documented impact \/ fix<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Federal remediation deadline<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE-2026-42016<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">JFrog\u00a0Artifactory<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Incorrect authorization<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">8.1<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Token privilege escalation; upgrade to an applicable fixed Artifactory release<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">September 25, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE-2026-42018<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">JFrog\u00a0Artifactory<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Improper authentication<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">7.5<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Anonymous-user token exposure; upgrade to an applicable fixed Artifactory release<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">September 25, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE-2026-84869<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">ConnectWise ScreenConnect<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Improper privilege management \/ missing authorization<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">9.9, CVSS v3.1<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Upgrade to ScreenConnect 26.6.5 or later<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">September 14, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE-2026-67277<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">MikroTik\u00a0RouterOS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Missing authentication \/ bandwidth-test flaw<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">8.8, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Kernel memory disclosure or remote DoS; update RouterOS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">September 13, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE-2026-86060<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">MikroTik\u00a0RouterOS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Argument handling in SSH login<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">9.2, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Privilege escalation; update RouterOS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">September 13, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>CISA&#8217;s KEV designation establishes evidence of active exploitation. However, it does not mean every publicly documented technique was used in every observed attack.<\/p>\n<p>The remediation dates apply to U.S. Federal Civilian Executive Branch agencies. Private-sector organizations can use KEV inclusion as a prioritization signal alongside their own exposure and risk assessments.<\/p>\n<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42016?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=artifactory_screenconnect_routeros_vulnerabilities\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-42016<\/a> and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42018?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=artifactory_screenconnect_routeros_vulnerabilities\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-42018<\/a> are actively exploited JFrog Artifactory vulnerabilities that attackers have chained toward administrative control. <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84869?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=artifactory_screenconnect_routeros_vulnerabilities\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-84869<\/a> affects ScreenConnect clients before 26.6.5, while <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-67277?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=artifactory_screenconnect_routeros_vulnerabilities\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-67277<\/a> and <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-86060?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=artifactory_screenconnect_routeros_vulnerabilities\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-86060<\/a> affect separate MikroTik RouterOS functions.<\/p>\n<h2>How Artifactory Vulnerabilities CVE-2026-42016 and CVE-2026-42018 Lead to Admin Access<\/h2>\n<p>CVE-2026-42018 can return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled.<\/p>\n<p>CVE-2026-42016 is a <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-privilege-escalation\/\">privilege-escalation<\/a> flaw in which Artifactory validates a token&#8217;s signature and issuer without correctly enforcing its scope.<\/p>\n<p>Neither issue independently provides the complete unauthenticated-to-administrator path.<\/p>\n<p>Researchers reported attackers chaining the vulnerabilities between August 15 and September 8, 2026. An unauthenticated request first obtained an internal anonymous-user JWT through CVE-2026-42018. Attackers then exploited CVE-2026-42016 to obtain a token with administrator scope.<\/p>\n<p>Across compromised Artifactory instances, Wiz observed post-exploitation activity that included persistent administrator accounts, malicious Groovy plugins and custom Rust backdoors with command-and-control capabilities. Wiz notes that no single actor performed every documented action.<\/p>\n<p>The compromise also creates software supply-chain risk because Artifactory repositories store and distribute artifacts used in development and deployment workflows.<\/p>\n<p>JFrog lists multiple fixed releases for CVE-2026-42018 across supported branches. CVE-2026-42016 affects self-hosted Artifactory versions before 7.133.11. Therefore, administrators should identify their deployed branch and apply the corresponding vendor-supported update.<\/p>\n<h2>How ScreenConnect Vulnerability CVE-2026-84869 Enables File Transfer and Execution<\/h2>\n<p>CVE-2026-84869 affects ScreenConnect clients before version 26.6.5. In certain circumstances, the flaw may let an attacker transfer and execute files through an active remote session without authorization or Host confirmation. ConnectWise states that the flaw does not affect ScreenConnect servers.<\/p>\n<p>ConnectWise states that Cloud deployments have been updated automatically. Cloud customers should reinstall Host clients and update Access agents. On-premises customers should upgrade the ScreenConnect server to version 26.6.5, then reinstall Host clients and update Access agents.<\/p>\n<p>Security teams should also investigate suspicious endpoint activity instead of treating an infrastructure update alone as evidence that previously exposed endpoints are clean.<\/p>\n<p>Unexpected file transfers, process execution or remote-access activity deserve additional review where ScreenConnect was exposed during the relevant period.<\/p>\n<h2>How RouterOS Vulnerabilities CVE-2026-67277 and CVE-2026-86060 Differ<\/h2>\n<p>The two RouterOS vulnerabilities in the CISA KEV update affect different services and should not be treated as one exploit chain.<\/p>\n<p>CVE-2026-86060 affects the RouterOS SSH login mechanism. A crafted username can manipulate session privileges, resulting in full administrative privileges.<\/p>\n<p>However, CVE-2026-86060 is only one component of the documented MikroTrick takeover chain. CERT Polska observed attackers chaining it with CVE-2026-67276 to gain unauthenticated administrative control over RouterOS devices with SSH exposed to public networks.<\/p>\n<p>CVE-2026-67277 is different.<\/p>\n<p>It affects RouterOS&#8217;s bandwidth-test service. An unauthenticated client can reach a state that should require authentication. Additional packet-handling weaknesses can then expose kernel memory or trigger a remote denial of service and system restart.<\/p>\n<p>Therefore, CVE-2026-67277 should not be described as the first stage of the confirmed MikroTrick takeover chain.<\/p>\n<p>MikroTik released fixes in RouterOS 7.25 beta 3, 7.24.2, 7.23.4 and 6.49.21. The vendor recommends preventing SSH access from untrusted networks.<\/p>\n<p>After upgrading, administrators should review RouterOS logs for compromise indications and inspect the configuration for unknown scripts, users or other unrecognized changes. MikroTik recommends inspecting the configuration even when RouterOS does not indicate that the device has been flagged.<\/p>\n<h2>How Should Enterprises Respond to These CISA KEV Vulnerabilities?<\/h2>\n<p>Enterprises should treat these Artifactory, ScreenConnect and RouterOS vulnerabilities as three separate remediation and investigation workflows.<\/p>\n<ol>\n<li><strong>Artifactory:<\/strong> identify affected self-hosted deployments and apply the fixed release for the deployed branch. Review administrator accounts, plugins and other unexpected changes.<\/li>\n<li><strong>ScreenConnect:<\/strong> upgrade affected installations to version 26.6.5 or later. Follow ConnectWise guidance for Host clients and Access agents. Investigate unexpected file transfers, process execution and remote-access activity.<\/li>\n<li><strong>RouterOS:<\/strong> install an applicable fixed release, including RouterOS 7.25 beta 3, 7.24.2, 7.23.4 or 6.49.21. Prevent SSH access from untrusted networks, review available compromise indications and inspect the configuration for unauthorized changes.<\/li>\n<\/ol>\n<p>Patching closes the documented vulnerability. It does not establish whether exploitation occurred before remediation.<\/p>\n<p>That distinction matters most for systems exposed during a known exploitation window.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/IT-admins-guide-to-patch-management-with-hexnode-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>IT Admin\u2019s Guide to Patch Management with Hexnode<\/h4><p>Learn how IT teams can identify, deploy, track and manage patches across supported endpoints with Hexnode.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/it-admins-guide-to-patch-management-with-hexnode\/\" aria-label=\"IT Admin\u2019s Guide to Patch Management with Hexnode\"><\/a><\/div><\/div><\/div>\n<h2>Where Hexnode Fits Into Endpoint Remediation and Investigation<\/h2>\n<p>The most direct Hexnode connection exists at the managed endpoint layer. Hexnode complements vendor remediation rather than replacing application- or network-level fixes.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can support patch and compliance workflows, while <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can support threat hunting, investigation and response.<\/p>\n<h3>Track Endpoint Patch and Compliance Posture with Hexnode UEM<\/h3>\n<p>Hexnode UEM provides advanced patch-management workflows for supported Windows and macOS endpoints. Administrators can manage OS updates on both platforms, while supported application-patching capabilities vary by platform and patch workflow.<\/p>\n<p>For this incident, Hexnode UEM is most relevant to <a href=\"https:\/\/www.hexnode.com\/uem\/features\/patch-and-update-management\/\">patch management<\/a>, device inventory and compliance workflows on managed endpoints.<\/p>\n<p>Hexnode UEM device and compliance reports can help administrators identify managed devices and review their compliance status.<\/p>\n<p>If the required ScreenConnect client package is available in a format supported by Hexnode UEM, IT teams can add the updated enterprise app to the Hexnode app inventory and distribute it to managed endpoints through supported app-deployment workflows. Teams should still follow ConnectWise&#8217;s documented remediation procedure for Host clients and Access agents.<\/p>\n<p>However, organizations should follow JFrog, ConnectWise and MikroTik\u2019s documented remediation procedures unless their Hexnode deployment workflow explicitly supports the required update.<\/p>\n<p>Patch management is only one part of post-exploitation response.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-XDR-IS-stronger-thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how integrating endpoint management with XDR can connect proactive device management with threat investigation and response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Investigate Suspicious ScreenConnect Endpoint Activity with Hexnode XDR<\/h3>\n<p>The ScreenConnect vulnerability creates a more direct endpoint-security use case.<\/p>\n<p>Hexnode XDR supports threat hunting through a query engine that helps security teams investigate suspicious endpoint activity.<\/p>\n<p>Documented response actions include Isolate Device, Kill Process, Kill Process Tree and Quarantine File. Analysts can terminate an identified malicious process or use Kill Process Tree to terminate that process and its spawned child processes. This can help contain an execution chain if suspicious activity identified during investigation includes malicious parent-child processes.<\/p>\n<p>These controls do not patch CVE-2026-84869. They also do not establish that Hexnode XDR specifically detects exploitation of this vulnerability.<\/p>\n<p>The RouterOS and Artifactory fixes must likewise occur at their respective network-appliance and application infrastructure layers.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Do CVE-2026-67277 and CVE-2026-86060 form the MikroTrick attack chain?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. CERT Polska documented the MikroTrick takeover chain using CVE-2026-67276 with CVE-2026-86060. CVE-2026-67277 separately affects the RouterOS bandwidth-test service.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does upgrading to ScreenConnect 26.6.5 require endpoint-side action?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. ConnectWise states that customers should reinstall Host clients and update Access agents. On-premises customers must also upgrade the ScreenConnect server to version 26.6.5.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Patch the Vulnerability, Then Investigate the Exposure Window<\/h3>\n<p>The Artifactory, ScreenConnect and RouterOS vulnerabilities span three different enterprise attack surfaces.<\/p>\n<p>Artifactory demonstrates how two authorization and authentication weaknesses can be chained toward administrative access. ScreenConnect exposes a security boundary inside trusted remote-support sessions. RouterOS shows how network-management services can expose paths to memory disclosure, disruption or privileged router access.<\/p>\n<p>Enterprises should take two steps: apply each vendor\u2019s remediation and investigate systems exposed before the fix. A successful patch closes the documented flaw. Incident review determines whether attackers got there first.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Patch and Compliance Management<\/h5><p>Manage supported endpoint updates, compliance workflows and device visibility with Hexnode UEM.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your 14-Day Free Trial<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>CISA recently added five actively exploited Artifactory, ScreenConnect and RouterOS vulnerabilities to its Known Exploited&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1713,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[20,21],"class_list":["post-1687","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-and-vpn","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA KEV: Artifactory, ScreenConnect, RouterOS Vulnerabilities<\/title>\n<meta name=\"description\" content=\"CISA flags exploited Artifactory, ScreenConnect and RouterOS vulnerabilities. Review affected CVEs, attack paths, fixes and response steps.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA KEV: Artifactory, ScreenConnect, RouterOS Vulnerabilities\" \/>\n<meta property=\"og:description\" content=\"CISA flags exploited Artifactory, ScreenConnect and RouterOS vulnerabilities. Review affected CVEs, attack paths, fixes and response steps.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-16T09:37:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T06:44:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities-1024x576.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities\",\"datePublished\":\"2026-09-16T09:37:59+00:00\",\"dateModified\":\"2026-09-21T06:44:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/\"},\"wordCount\":1454,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp\",\"articleSection\":[\"Network and VPN\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/\",\"name\":\"CISA KEV: Artifactory, ScreenConnect, RouterOS Vulnerabilities\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp\",\"datePublished\":\"2026-09-16T09:37:59+00:00\",\"dateModified\":\"2026-09-21T06:44:32+00:00\",\"description\":\"CISA flags exploited Artifactory, ScreenConnect and RouterOS vulnerabilities. Review affected CVEs, attack paths, fixes and response steps.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp\",\"width\":1920,\"height\":1080,\"caption\":\"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cisa-kev-artifactory-screenconnect-routeros\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA KEV: Artifactory, ScreenConnect, RouterOS Vulnerabilities","description":"CISA flags exploited Artifactory, ScreenConnect and RouterOS vulnerabilities. Review affected CVEs, attack paths, fixes and response steps.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/","og_locale":"en_US","og_type":"article","og_title":"CISA KEV: Artifactory, ScreenConnect, RouterOS Vulnerabilities","og_description":"CISA flags exploited Artifactory, ScreenConnect and RouterOS vulnerabilities. Review affected CVEs, attack paths, fixes and response steps.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-16T09:37:59+00:00","article_modified_time":"2026-09-21T06:44:32+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities-1024x576.png?format=webp","type":"image\/png"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities","datePublished":"2026-09-16T09:37:59+00:00","dateModified":"2026-09-21T06:44:32+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/"},"wordCount":1454,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp","articleSection":["Network and VPN","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/","name":"CISA KEV: Artifactory, ScreenConnect, RouterOS Vulnerabilities","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp","datePublished":"2026-09-16T09:37:59+00:00","dateModified":"2026-09-21T06:44:32+00:00","description":"CISA flags exploited Artifactory, ScreenConnect and RouterOS vulnerabilities. Review affected CVEs, attack paths, fixes and response steps.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/CISA-KEV-Flags-Exploited-Artifactory-ScreenConnect-and-RouterOS-Vulnerabilities.png?format=webp","width":1920,"height":1080,"caption":"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cisa-kev-artifactory-screenconnect-routeros\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CISA KEV Flags Exploited Artifactory, ScreenConnect and RouterOS Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1687","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1687"}],"version-history":[{"count":4,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1687\/revisions"}],"predecessor-version":[{"id":1749,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1687\/revisions\/1749"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1713"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1687"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1687"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}