CISA Adds Five Actively Exploited Vulnerabilities to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five new security flaws to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them due to active exploitation. The vulnerabilities impact JFrog Artifactory (CVE-2026-42016, CVE-2026-42018), ConnectWise ScreenConnect (CVE-2026-84869), and MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060). These flaws range from incorrect authorization and improper authentication to improper privilege management and missing authentication for critical functions, with CVSS scores as high as 9.9.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai