
CISA added six vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog across September 10 and 11, 2026.
The additions affect MikroTik RouterOS, ConnectWise ScreenConnect, GitLab, and JFrog Artifactory.
September 10, 2026
1. CVE-2026-67277 — MikroTik RouterOS
Vulnerability: Missing Authentication for a Critical Function
Product: MikroTik RouterOS
Severity: High
CISA KEV: September 10, 2026
Due date: September 13, 2026
CVE-2026-67277 affects the RouterOS bandwidth-test (btest) service.
The vulnerability allows an unauthenticated attacker to interact with the service before authentication has been completed. Under specific conditions, the attacker can cause the device to disclose uninitialized kernel memory.
The flaw can also trigger an unsigned integer underflow, resulting in abnormal packet fragmentation and potentially causing the RouterOS kernel to restart.
The vulnerability therefore presents both information-disclosure and denial-of-service risks.
Organizations should identify RouterOS systems exposing the affected functionality and upgrade to the applicable fixed RouterOS release.
2. CVE-2026-86060 — MikroTik RouterOS
Vulnerability: Improper Neutralization of Argument Delimiters in a Command
Product: MikroTik RouterOS
Severity: Critical
CISA KEV: September 10, 2026
Due date: September 13, 2026
CVE-2026-86060 is an argument-injection vulnerability affecting RouterOS.
A specially crafted username can manipulate the RouterOS command-processing behavior and alter the trusted policy mask.
Successful exploitation can result in privilege escalation, potentially allowing an attacker to obtain elevated privileges on the RouterOS device.
Because the vulnerability can be exploited remotely without requiring prior privileges or user interaction, exposed SSH services represent a particularly important attack surface.
CISA also identifies forensic triage as required, meaning organizations should investigate potentially affected devices for signs of compromise rather than treating remediation as a simple patching exercise.
September 11, 2026
3. CVE-2026-84869 — ConnectWise ScreenConnect
Vulnerability: Improper Privilege Management / Missing Authorization
Product: ConnectWise ScreenConnect
CISA KEV: September 11, 2026
Due date: September 14, 2026
CVE-2026-84869 affects the remote-support functionality of ScreenConnect.
The vulnerability can allow unauthorized file transfer and execution through an active remote session without the required host confirmation or authorization controls.
Because ScreenConnect provides remote administrative capabilities, exploitation can potentially provide an attacker with the ability to perform actions on connected systems beyond what should be permitted.
CISA has marked this vulnerability for forensic triage, making investigation of potentially exposed installations an important part of remediation.
Organizations should also determine whether their IT service providers or managed-service partners operate affected ScreenConnect infrastructure on their behalf.
4. CVE-2026-85706 — GitLab
Vulnerability: Path Traversal
Product: GitLab Community Edition / Enterprise Edition
CISA KEV: September 11, 2026
Due date: September 14, 2026
CVE-2026-85706 is a path-traversal vulnerability in GitLab.
The flaw allows an unauthenticated attacker to manipulate paths through the repository commits API, potentially resulting in arbitrary file disclosure.
The vulnerability is particularly significant because GitLab servers can contain sensitive development information, configuration files, credentials, tokens and other data used by CI/CD environments.
Affected GitLab installations should be upgraded to the applicable fixed versions.
CISA has also designated this vulnerability for forensic triage, so organizations should investigate potentially exposed systems for evidence of exploitation.
5. CVE-2026-42018 — JFrog Artifactory
Vulnerability: Improper Authentication
Product: JFrog Artifactory
Severity: High
CISA KEV: September 11, 2026
Due date: September 25, 2026
CVE-2026-42018 is an authentication weakness in JFrog Artifactory.
Under affected configurations, particularly when anonymous access has been disabled, an unauthenticated attacker may still obtain an internal anonymous-user token.
The exposed token can potentially be used to access resources that should not be available to an unauthenticated user.
The vulnerability therefore creates a risk of unauthorized access and information disclosure.
Organizations should upgrade affected Artifactory installations and verify that anonymous access and token-handling configurations are operating as intended.
6. CVE-2026-42016 — JFrog Artifactory
Vulnerability: Incorrect Authorization
Product: JFrog Artifactory
CISA KEV: September 11, 2026
Due date: September 25, 2026
CVE-2026-42016 is an authorization vulnerability that can result in privilege escalation.
The flaw involves inadequate validation of the permissions associated with an authentication token. Under vulnerable conditions, an attacker can potentially use a token in a way that provides privileges beyond those intended for that token.
Successful exploitation can therefore allow an attacker to escalate privileges within Artifactory.
Organizations should upgrade to the applicable fixed release and review privileged accounts and token usage where exploitation is suspected.
At a Glance
September 10 — 2 vulnerabilities
- CVE-2026-67277 — MikroTik RouterOS — Missing Authentication
- CVE-2026-86060 — MikroTik RouterOS — Argument Injection / Privilege Escalation
September 11 — 4 vulnerabilities
- CVE-2026-84869 — ConnectWise ScreenConnect — Improper Privilege Management / Missing Authorization
- CVE-2026-85706 — GitLab — Path Traversal
- CVE-2026-42018 — JFrog Artifactory — Improper Authentication
- CVE-2026-42016 — JFrog Artifactory — Incorrect Authorization / Privilege Escalation
Total: 6 KEV additions across two days.
The immediate remediation deadlines are September 13 for the two MikroTik vulnerabilities, September 14 for ScreenConnect and GitLab, and September 25 for the two JFrog Artifactory vulnerabilities.




Thanks for sharing this important cybersecurity update. Six vulnerabilities being added to CISA’s KEV Catalog in just two days is certainly a reminder that organizations need to stay vigilant. The MikroTik RouterOS issues, in particular, highlight the importance of timely patching, securing exposed services, and investigating systems for possible compromise—not merely installing the fix. 🔐
Cybersecurity is no longer just an IT concern; it is an organizational responsibility.