PGH Networks

CISA Flags Actively Exploited ScreenConnect and RouterOS Flaws

September 14, 2026· PGH Networks Team· 5 min readBusiness & Tech Insights
CISA Flags Actively Exploited ScreenConnect and RouterOS Flaws

What happened

The U.S. Cybersecurity and Infrastructure Security Agency has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after reports of active exploitation in the wild. The affected products are JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. One of the flaws, CVE-2026-42016, is an incorrect authorization issue carrying a CVSS score of 8.1. This was reported via feeds.feedburner.com in The Hacker News coverage of the KEV additions.

Two notes on scope, because precision matters here. First, the reporting names the affected product families but we are not going to guess at the remaining four CVE identifiers, the specific vulnerable version ranges, or the KEV remediation due dates — verify those directly in the CISA KEV catalog and each vendor's advisory before you plan a maintenance window. Second, KEV inclusion is not a theoretical severity rating. It means someone is already using these flaws against real targets, which changes the calculus from "patch on the next cycle" to "confirm exposure now."

man in blue dress shirt sitting on rolling chair inside room with monitors

Why this matters for Pittsburgh small and mid-sized businesses

ScreenConnect is the one that should make you sit up. Remote monitoring and management tooling is how IT gets work done at a 40-person CPA firm or a 120-person manufacturer without sending a technician to every desk. That same tooling is a dream target: it runs with high privilege, it is trusted by endpoints by design, and a single compromised instance can reach every machine it manages. Attackers have repeatedly gone after remote-access platforms precisely because it is a one-to-many path into downstream businesses. If you or any vendor in your environment runs ScreenConnect — self-hosted or cloud — this is your week to confirm version and patch status in writing.

MikroTik RouterOS matters for a different reason. It shows up in smaller offices, satellite locations, shop-floor networks, and warehouse Wi-Fi builds, often installed years ago by whoever wired the space and never touched since. Edge network gear rarely lands on anyone's patch report, which is exactly why it gets exploited. If your Robinson or Cranberry satellite office has a router nobody can name the vendor of, that is a finding.

JFrog Artifactory is narrower — it is an artifact repository used by teams that build software. If you have internal developers or a product engineering group, this is a supply-chain concern: compromise the repository and you can poison what gets deployed.

Now layer on compliance. If you handle protected health information, HIPAA expects documented vulnerability management and timely remediation, and an exploited remote-access tool is a textbook breach path. Defense contractors working toward CMMC Level 2 have explicit controls for flaw remediation and remote access — SI.L2-3.14.1 and the AC family both come into play, and an unpatched, actively exploited remote-access server is not a defensible position during an assessment. Financial services firms under FTC Safeguards and anyone maintaining a SOC 2 report will need evidence that they identified affected assets and acted. Legal and professional services firms should assume client security questionnaires will ask about these CVEs within the next quarter.

What to do about it this week

  1. Inventory every remote-access tool in your environment, including shadow instances. Ask your IT provider for a written list of RMM and remote-support agents deployed on your endpoints, plus any self-hosted management servers. Then check whether contractors, line-of-business vendors, or your accounting or ERP integrator installed their own.
  2. Confirm ScreenConnect version and patch state in writing. If a provider manages it for you, request the specific build number and the date it was patched against the KEV-listed CVE. "We're up to date" is not evidence. If you self-host, apply the vendor update and then reset service account credentials and API keys.
  3. Pull the actual CVE list and due dates from the CISA KEV catalog. Federal agencies have binding remediation deadlines; private companies do not, but the KEV entry dates give you a reasonable internal target. Set your own deadline — 14 days from today, September 14, 2026, is a defensible standard for actively exploited flaws.
  4. Audit your network edge for MikroTik and other unmanaged gear. Walk each location. Identify router and switch make, model, and firmware. Verify management interfaces are not reachable from the internet, that default credentials are gone, and that firmware updates are on a schedule. Bring this under your patch management program rather than treating it as one-off cleanup.
  5. Check Artifactory only if it applies, and check it properly. If you run an artifact repository, update it, review authentication settings and token scopes, and look at access logs for unusual pulls or pushes.
  6. Hunt for post-exploitation activity, not just patch gaps. Patching does not evict an attacker who is already in. Review EDR telemetry for new local admin accounts, unexpected scheduled tasks, unfamiliar remote sessions, and outbound connections from management servers. Correlate with Microsoft 365 sign-in logs for anomalous access in the same window.
  7. Document all of it. Assets checked, versions found, actions taken, dates. That record is what satisfies an auditor, an insurance carrier, or a client questionnaire six months from now — and it costs almost nothing to capture while you are already doing the work.

man standing beside another sitting man using computer

How we help

PGH Networks manages patching, endpoint detection, and network hardening for small and mid-sized businesses across Western Pennsylvania, and our cybersecurity practice tracks KEV additions so client environments get triaged as advisories land rather than at the next quarterly review. If you are not sure who is responsible for the remote-access tooling on your network, or you want a technology roadmap that includes edge devices and compliance evidence instead of just servers and laptops, we can start with a straightforward exposure review.

Talk to us

Call 724.888.7007 or reach us through the contact form and we will help you confirm where you stand on these five vulnerabilities.

Share

Related reading

Call usBook a meeting