Security · 2 MIN READ

CISA Adds Five Actively Exploited Flaws, Including RouterOS

CISA has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog. The RouterOS entry makes accurate network inventory and asset-level vulnerability tracking especially important for remediation teams.

CISA Adds Five Actively Exploited Flaws, Including RouterOS

CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. Reports of exploitation in the wild mean these are no longer theoretical risks, making rapid asset identification and remediation essential.


What CISA Added

The advisory covers five security flaws across three distinct technologies. One of the listed vulnerabilities is CVE-2026-42016, an incorrect authorization issue with a CVSS score of 8.1.

  • JFrog Artifactory

  • ConnectWise ScreenConnect

  • MikroTik RouterOS

The full report provides the individual vulnerability details and exploitation context needed to determine which products require attention.


Why the RouterOS Flaw Matters

The RouterOS entry brings the advisory directly into the network-infrastructure domain. Because CISA added the flaw after reports of active exploitation, teams should promptly identify RouterOS assets, verify their exposure against the complete advisory, and follow the applicable remediation guidance.

A reliable response depends on knowing which devices exist, who owns them, and whether remediation has been completed. Incomplete inventories can leave an affected router outside the patching workflow even when the vulnerability itself is well understood.


Turning a KEV Alert Into Action

A KEV addition should trigger an asset-focused process rather than remain a general security notification.

  • Locate potentially affected products in the asset inventory.

  • Confirm product and vulnerability mappings using the full CISA and vendor information.

  • Assign an owner and prioritize actively exploited flaws.

  • Preserve relevant configurations before making network changes.

  • Record remediation status at the individual asset level.

  • Validate that no affected device was missed after the change window.


How ConnectMyAssets Helps

ConnectMyAssets is an on-prem platform for managing supported multi-vendor network infrastructure, with all operational data remaining inside the organization. Its modules help turn vulnerability intelligence into controlled infrastructure work:

  • CVE Tracking associates vulnerability exposure with individual managed assets, helping teams prioritize devices rather than work from generic product lists.

  • Dynamic CMDB maintains an automatically discovered inventory and LLDP topology for supported network equipment.

  • Backup & History preserves configuration versions with SHA256 verification and provides one-click rollback when an approved change causes problems.

  • Automation & ZTP supports coordinated deployment of approved changes across managed devices.

  • Compliance Engine can incorporate CISA-aligned controls and weighted scoring into the broader remediation process.

MikroTik is not currently listed among the supported ConnectMyAssets vendors, so the RouterOS device itself should be handled through the organization’s established MikroTik remediation workflow. ConnectMyAssets provides these capabilities for supported network gear from vendors including Cisco, Fortinet, Palo Alto, Juniper, Aruba, Arista, F5, Check Point, Huawei, Nokia, SonicWall, Stormshield, Ubiquiti, and Extreme.

Source: The Hacker News

Share this articleLinkedIn ↗Email ↗

Keep exploring.

All articles
Security

Critical Check Point Management Flaw Allows Root Code Execution

A critical vulnerability in Check Point Security Management and Log Servers could let an unauthenticated network attacker execute code as root. Because the management server controls firewall policy and administrator access, organizations should apply the LivePatch fix and verify every potentially exposed system.

Read article
Security

Check Point Management-Server RCE: What to Track

CERT-FR has reported a vulnerability in Check Point products that can allow remote arbitrary code execution. Administrators should identify affected management assets, apply the required vendor updates, and search SmartConsole logs for the login-failure pattern highlighted in the advisory.

Read article
Security

Cisco ISE Zero-Day Under Active Attack

Cisco has disclosed a maximum-severity authentication-bypass vulnerability in ISE that is already being exploited. Network teams should identify affected systems, follow Cisco’s remediation guidance, and document patch or mitigation status across their network-access infrastructure.

Read article