The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog with five security flaws confirmed to be under active attack. The vulnerabilities affect ConnectWise ScreenConnect, JFrog Artifactory, and MikroTik RouterOS—systems integral to remote support, software development, and network infrastructure. This action transforms these from theoretical risks into compliance-driven, emergency patching priorities.

While issued by a U.S. federal agency, the advisory carries global implications. The widespread use of these tools means organizations worldwide—including managed service providers (MSPs), development firms, and enterprises with MikroTik networks—face direct exposure. The primary danger lies in the diverse attack surfaces; a single entity could be compromised through multiple vectors, from remote access to build pipelines and network perimeters.

CISA's KEV listing mandates remediation for federal agencies by specific deadlines, but it serves as a definitive global signal for urgent action across all sectors. The specific vulnerabilities added include:

  • CVE-2026-42016 (CVSS 8.1) in ConnectWise ScreenConnect: An authorization flaw that could allow unauthorized remote access, posing a high-severity threat for any organization using the software for support or remote work.
  • JFrog Artifactory Flaws: Multiple vulnerabilities in this critical artifact repository manager. Compromise could enable attackers to poison software builds and releases, representing a severe supply chain attack vector.
  • MikroTik RouterOS Vulnerabilities: Flaws in this widely deployed networking OS can be exploited for network interception, lateral movement, or to conscript devices into botnets.

The clear directive for IT teams is to initiate emergency patching and asset verification immediately.

For Managed Service Providers (MSPs): The ScreenConnect flaw is your top priority. Conduct an immediate audit to identify all instances of the software and update to the vendor-patched version without delay. A compromise here could cascade across your entire client base.

For DevOps and Development Teams: The Artifactory risk strikes at build integrity. Verify the security of your artifact repositories, apply patches, and scrutinize access logs for signs of a prior supply chain compromise.

For Network Administrators: Inventory all MikroTik devices and prioritize updating these often-targeted perimeter and distribution devices. Review configurations for any unauthorized changes.

The common thread is the need for immediate action. Active exploitation status elevates these flaws beyond routine maintenance into emergency territory. Teams should not wait for a scheduled maintenance window. Alongside patching, a review of access controls and enhanced logging across these systems is a critical defensive measure.

This update highlights a persistent reality: foundational IT components remain prime targets. Proactive asset management and rapid response to vendor and government advisories are essential to maintaining operational security.

For detailed CVE listings and official deadlines, refer to the CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog


美國網絡安全和基礎設施安全局(CISA)已更新其已知被利用漏洞(KEV)目錄,新增五個經確認正處於 active attack 狀態的安全漏洞。這些漏洞影響 ConnectWise ScreenConnect、JFrog Artifactory 及 MikroTik RouterOS——這些系統是遠端支援、軟件開發及網絡基礎設施不可或缺的組成部分。此舉將這些漏洞從理論風險轉化為合規要求驅動的緊急修補優先事項。

雖然該通告由美國聯邦機構發布,但具有全球影響力。這些工具的廣泛使用意味著全球各地的機構——包括管理服務供應商(MSP)、開發公司以及使用 MikroTik 網絡的企業——都面臨直接暴露的風險。主要危險在於攻擊面多樣;單一實體可能透過多個向量遭到入侵,涵蓋從遠端訪問、建構流水線到網絡邊界。

CISA 的 KEV 列表強制要求聯邦機構在特定期限內完成補救,但它同時作為一個明確的全球信號,敦促所有行業採取緊急行動。此次新增的特定漏洞包括:

  • ConnectWise ScreenConnect 中的 CVE-2026-42016(CVSS 8.1): 一個授權漏洞,可能允許未授權的遠端訪問,對任何使用該軟件進行支援或遠端工作的機構構成高嚴重性威脅。
  • JFrog Artifactory 漏洞: 這個關鍵的構件儲存庫管理器中存在多個漏洞。成功入侵可能使攻擊者能污染軟件建構與發布過程,構成嚴重的供應鏈攻擊向量。
  • MikroTik RouterOS 漏洞: 這個廣泛部署的網絡操作系統中的漏洞,可能被利用進行網絡竊聽、橫向移動,或將設備強行納入殭屍網絡。

給 IT 團隊的明確指示是:立即啟動緊急修補和資產驗證。

致管理服務供應商(MSP): ScreenConnect 漏洞是你們的首要任務。立即進行審計以找出該軟件的所有實例,並毫不延遲地更新至供應商提供的修補版本。此處的入侵可能級聯影響你的整個客戶群。

致 DevOps 和開發團隊: Artifactory 風險直接衝擊建構完整性。驗證你的構件儲存庫的安全性,套用修補程式,並仔細檢查訪問日誌,以尋找先前供應鏈入侵的跡象。

致網絡管理員: 盤點所有 MikroTik 設備,並優先更新這些經常成為攻擊目標的邊界和分發設備。審查配置,查找任何未經授權的更改。

共同點是需要立即行動。Active exploitation 狀態將這些漏洞提升到超越日常維護的緊急層面。團隊不應等待預定的維護窗口。除了修補程式,審查這些系統的存取控制和增強日誌記錄,也是一項關鍵的防禦措施。

此更新凸顯了一個持續存在的現實:基礎 IT 組件仍然是首要攻擊目標。主動的資產管理以及對供應商和政府通告的快速響應,對於維持運營安全至關重要。

如需詳細的 CVE 清單和官方期限,請參閱 CISA 已知被利用漏洞目錄:https://www.cisa.gov/known-exploited-vulnerabilities-catalog

新聞來源 / Original News Source