Skip to content
feed: live
>_0dayNews
cisa kev
● Breaking

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow

CISA added five exploited flaws in MikroTik RouterOS, ConnectWise ScreenConnect, and JFrog Artifactory. Federal patch deadline for RouterOS is today, September 13.

CISA KEV: RouterOS Deadline Today, ScreenConnect Tomorrow
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

MikroTik RouterOS patches are due today for U.S. federal agencies. ConnectWise ScreenConnect follows tomorrow. Both involve confirmed active exploitation. JFrog Artifactory rounds out this batch with a September 25 deadline, but active attack chains against those flaws make the calendar date largely irrelevant for anyone running Artifactory on the open internet.

CISA added all five to the Known Exploited Vulnerabilities catalog between September 10 and 11, 2026, alongside the ongoing Artifactory backdoor campaign already documented here.

RouterOS: due today

CVE-2026-86060 (CVSS 9.8, critical) is a privilege escalation flaw in RouterOS’s SSH login path. Usernames starting with a prohibited character allow an unauthenticated attacker to alter the trusted RouterOS policy mask. Per the NVD entry, the fix is in RouterOS 6.49.21, 7.23.4 (Long-term), and 7.24.2 (Stable).

CVE-2026-67277 (CVSS 8.2, high) is a missing authentication flaw in the RouterOS btest service. An unauthenticated client can trigger kernel memory disclosure and, in some cases, denial of service. The same patch versions apply: 6.49.21, 7.23.4 (Long-term), and 7.24.2 (Stable).

Both carry the same federal deadline: today. Check your RouterOS release channel and update. MikroTik has been in CISA’s crosshairs repeatedly this month: an exploited SSH auth bypass was patched less than a week ago.

ScreenConnect: due September 14

CVE-2026-84869 (CVSS 9.9, critical) lets an attacker transfer and execute files through an active ScreenConnect session without host authorization or confirmation. ConnectWise’s security bulletin and the NVD entry have patch details. The federal deadline is tomorrow. Any internet-exposed ScreenConnect instance should be treated as urgent regardless of the federal mandate.

Artifactory: due September 25

Two JFrog Artifactory flaws close out the batch.

CVE-2026-42016 (CVSS 8.1, high): Artifactory validates a token’s signature and issuer but not its scope, creating a privilege escalation path for anyone who can obtain a token.

CVE-2026-42018 (CVSS 7.5, high): Artifactory returns an internal anonymous-user token to unauthenticated callers, even with anonymous access disabled. Threat actors are already chaining these two with additional Artifactory flaws to reach administrative control and drop a Rust backdoor. That campaign is covered in full here. The JFrog advisory and NVD entry have version and remediation specifics.

The September 25 deadline is a federal compliance date. If you run Artifactory and haven’t patched, patch this week.

Patch order

RouterOS first (6.49.21 / 7.23.4 / 7.24.2) today. ScreenConnect by September 14. Artifactory before September 25, sooner given active exploitation. CISA’s September 11-12 KEV batch covered Cisco, Citrix, and Fortinet separately.

Related CVEs
  • [ HIGH ]CVE-2026-42016JFrog Artifactory Incorrect Authorization Vulnerability
  • [ HIGH ]CVE-2026-42018JFrog Artifactory Improper Authentication Vulnerability
  • [ CRITICAL ]CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
  • [ HIGH ]CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
  • [ CRITICAL ]CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

Found this useful? Share it.