What happened
Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Attackers are already using this issue in real-world attacks, so exposed systems may need both remediation and investigation for earlier compromise.
The significance for defenders depends on whether the organizations, technologies or attack path described in the reporting overlap with their own environment. Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What security teams should do now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-42016 and validate the affected path after remediation.
What is not yet confirmed
- The full attack sequence has not yet been publicly confirmed.
- Who was responsible has not yet been confirmed publicly.