🧭 Decision Radar
Relevance for Algeria
High
▾
Infrastructure Ready?
Partial
▾
Skills Available?
Partial
▾
Action Timeline
Immediate
▾
ARPT, Algérie Télécom, local ISPs, MSPs using ConnectWise, DevOps teams running self-hosted Artifactory instances
Decision Type
Operational
▾
Quick Take: Algerian ISPs, small businesses, and IT teams running MikroTik RouterOS, JFrog Artifactory, or ConnectWise ScreenConnect should patch against these five CVEs immediately — CISA’s KEV listing confirms active exploitation, and RouterOS’s ubiquity in Algeria’s networking market makes this advisory unusually locally relevant compared to most CISA additions.
Five Flaws Across Three Widely Deployed Products
CISA’s Known Exploited Vulnerabilities catalog tracks vulnerabilities confirmed to be under active exploitation, and its mid-September 2026 additions span three products common in enterprise DevOps and remote-support environments. The five CVEs are:
- CVE-2026-42016 (CVSS 8.1) — JFrog Artifactory, an incorrect authorization flaw that can lead to privilege escalation because the platform validates a token’s signature and issuer but not its scope.
- CVE-2026-42018 (CVSS 7.5) — JFrog Artifactory, an improper authentication flaw that can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled, potentially leaking sensitive resources.
- CVE-2026-84869 (CVSS 9.9) — ConnectWise ScreenConnect, an improper privilege management and missing authorization flaw that lets an attacker transfer and execute files through an active remote session without authorization; CISA’s advisory notes the issue does not affect ScreenConnect servers themselves.
- CVE-2026-67277 and CVE-2026-86060 — MikroTik RouterOS, a pair of flaws that CERT Polska first reported seeing exploited in the wild, nicknamed “MikroTrick” by the Polish security team.
Attackers have been observed chaining the two Artifactory vulnerabilities to escalate privileges and access sensitive resources, and separately chaining the ScreenConnect and RouterOS flaws to gain administrative control, deploy backdoors, and seize vulnerable devices without authentication, according to the reporting on CISA’s advisory.
Why These Specific Products Matter
JFrog Artifactory is a widely deployed artifact repository sitting at the center of many organizations’ software build and deployment pipelines — a compromise there can propagate into every downstream system that pulls packages from it. ConnectWise ScreenConnect is remote-access software used heavily by managed service providers, making it an attractive target because a single compromised instance can provide a foothold into many downstream client networks. MikroTik RouterOS runs on networking hardware deployed at massive scale globally, including in cost-sensitive markets where routers often run without frequent firmware updates — exactly the profile of device that becomes part of a botnet once a remote-exploitable flaw is public.
1. Patch or isolate immediately if you run any of these three products
Federal civilian agencies in the US face binding deadlines to remediate these flaws, and CISA’s inclusion in the KEV catalog is a strong signal that exploitation is not theoretical. Any organization running self-hosted Artifactory, ScreenConnect, or RouterOS should treat this as an urgent patch cycle, not a routine update.
2. Audit remote-management tooling for exposure, not just patch status
Because ScreenConnect and RouterOS are both remote-access and remote-management tools, a compromise doesn’t just affect the vulnerable instance — it can be a pivot point into every system that instance manages. Security teams should audit not just whether the software is patched, but what access a compromised instance would grant an attacker.
3. Treat KEV catalog additions as a recurring signal to monitor, not a one-time alert
The pattern of DevOps infrastructure and remote-management tools appearing repeatedly in CISA’s KEV catalog suggests these categories remain high-value, frequently targeted attack surfaces. Organizations running self-hosted infrastructure should build a recurring process for checking new KEV entries against their own software inventory, rather than reacting only when a specific vendor’s flaw makes headlines.
Advertisement
What This Signals About the Current Threat Landscape
The specific combination of products flagged here — a software artifact repository, remote-support software, and consumer/SMB-grade networking hardware — reflects where attackers are finding the most reliable return on effort: infrastructure that is widely deployed, often self-managed without dedicated security teams, and positioned to provide broad downstream access once compromised. CISA’s KEV catalog additions are, in effect, a real-time map of where active exploitation is concentrated, and mid-September 2026’s additions point squarely at the software supply chain and remote-access layers that many organizations still under-prioritize relative to their internet-facing web applications.
Frequently Asked Questions
Which five vulnerabilities did CISA add to the KEV catalog?
Per the advisory, CISA added CVE-2026-42016 and CVE-2026-42018 (JFrog Artifactory), CVE-2026-84869 (ConnectWise ScreenConnect), and CVE-2026-67277 and CVE-2026-86060 (MikroTik RouterOS) in mid-September 2026.
How are attackers exploiting these flaws?
Attackers have been chaining the Artifactory flaws to escalate privileges and leak sensitive resources, and separately using the ScreenConnect and RouterOS vulnerabilities to gain administrative control, deploy backdoors, and seize vulnerable devices without authentication, according to the reporting on CISA’s advisory.
Why does MikroTik RouterOS matter especially for Algeria?
RouterOS runs on low-cost networking hardware widely deployed by ISPs and small businesses in cost-sensitive markets, including Algeria, where routers often go long periods without firmware updates — making the RouterOS flaws in this advisory particularly relevant to local network infrastructure.













