NPM · SEPTEMBER 2026 · CONFIRMED

Critical Vulnerabilities in artifactory, screenconnect, routeros: What You Need to Know

Severity
HIGH
CVSS
8.1
Affected component
artifactory (npm)
Patched version
Not yet available
CVE-2026-42016

The npm packages artifactory, screenconnect, and routeros have been added to CISA's KEV catalog due to active exploitation in the wild. CVE-2026-42016 is an incorrect authorization vulnerability with a CVSS score of 8.1.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. CVE-2026-42016 is an incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's scope. CVE-2026-84869 is an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect that could allow an attacker to file transfer and execute through an active remote session without authorization or host confirmation.

To assess your exposure, check if you are using any of the affected npm packages: artifactory, screenconnect, or routeros. If so, review the version you are using against the latest versions available to determine if you are running a vulnerable version. Consult the primary sources for the most up-to-date information on affected versions and patches.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using the npm packages artifactory, screenconnect, or routeros. Check the versions you are using against the latest versions available.

What should I do right now?

Upgrade to the latest versions of artifactory, screenconnect, and routeros that address the vulnerabilities and monitor for any signs of exploitation.

Has this been exploited in the wild?

Yes, CVE-2026-42016 has been confirmed to be exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats