CISA's KEV List Just Got Bigger: 5 Flaws Under Attack

·
Listen to this article~4 min
CISA's KEV List Just Got Bigger: 5 Flaws Under Attack

CISA adds five actively exploited flaws in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog. Here's what you need to know and do.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) just made a move that should get your attention if you run any kind of digital infrastructure. They've added five security flaws to their Known Exploited Vulnerabilities (KEV) catalog. And these aren't theoretical bugs. They're being actively exploited right now. The affected products? JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. If those names sound familiar, it's because they're everywhere. Artifactory handles your software artifacts. ScreenConnect is a remote support tool. RouterOS powers a massive number of routers and network devices. In other words, these aren't obscure tools. They're the backbone of a lot of businesses. ### What Exactly Got Added? Let's break down the specifics. The most notable one is CVE-2026-42016, which carries a CVSS score of 8.1. That's high. It's an incorrect authorization flaw. Translation: someone who shouldn't have access can potentially get in and do things they shouldn't. The other four flaws haven't been detailed here, but they're all serious enough to land on CISA's radar. CISA doesn't add things to the KEV catalog lightly. When a vulnerability shows up there, it means there's confirmed evidence of exploitation in the wild. Real attackers are using these flaws against real targets. This isn't a drill. ### Why This Matters for Your Business If you're using any of these products, you're potentially in the crosshairs. The KEV catalog exists for a reason: to give organizations a clear, actionable list of what to patch first. Federal agencies are required to remediate KEV entries within a set timeframe. But honestly, everyone should treat this list as a priority. Here's the thing: attackers love low-hanging fruit. If there's a known vulnerability with a public exploit, they'll use it. They don't need to be geniuses. They just need you to be slow. ### What You Should Do Right Now - Check if you're running JFrog Artifactory, ConnectWise ScreenConnect, or MikroTik RouterOS. If you are, don't wait. - Apply patches as soon as they're available. Vendors usually release fixes quickly once a flaw hits the KEV list. - If a patch isn't available yet, look for mitigations. Sometimes you can disable a feature or restrict access to buy yourself time. - Monitor your logs for unusual activity. Exploitation often leaves traces, but you have to look. - Consider your exposure. Are these systems internet-facing? If so, you're at higher risk. > "The KEV catalog is a signal, not a suggestion. When CISA adds something, it's because the bad guys are already using it." ### The Bigger Picture This isn't just about one set of vulnerabilities. It's a reminder that the threat landscape is always shifting. New flaws get discovered, exploited, and added to lists like this all the time. The organizations that stay safe are the ones that treat security as an ongoing process, not a one-time fix. So take a breath. Check your systems. Patch what you can. And keep an eye on that KEV catalog. It's one of the best early warning systems we've got.