Critical Vulnerabilities in artifactory, screenconnect, routeros: What You Need to Know
- Severity
- HIGH
- CVSS
- 8.1
- Affected component
- artifactory (npm)
- Patched version
- Not yet available
The npm packages artifactory, screenconnect, and routeros have been added to CISA's KEV catalog due to active exploitation in the wild. CVE-2026-42016 is an incorrect authorization vulnerability with a CVSS score of 8.1.
What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. CVE-2026-42016 is an incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's scope. CVE-2026-84869 is an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect that could allow an attacker to file transfer and execute through an active remote session without authorization or host confirmation.
To assess your exposure, check if you are using any of the affected npm packages: artifactory, screenconnect, or routeros. If so, review the version you are using against the latest versions available to determine if you are running a vulnerable version. Consult the primary sources for the most up-to-date information on affected versions and patches.
What to do about it
- Upgrade to the latest versions of artifactory, screenconnect, and routeros that address the vulnerabilities.
- Monitor for any signs of exploitation in your systems.
- Consult the primary sources for the most up-to-date information on affected versions and patches.
- Implement additional security measures to detect and respond to potential exploitation attempts.
- Stay informed about updates and patches released by the vendors of the affected packages.
How 0Day would have caught this
artifactory is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using the npm packages artifactory, screenconnect, or routeros. Check the versions you are using against the latest versions available.
What should I do right now?
Upgrade to the latest versions of artifactory, screenconnect, and routeros that address the vulnerabilities and monitor for any signs of exploitation.
Has this been exploited in the wild?
Yes, CVE-2026-42016 has been confirmed to be exploited in the wild.