← Back to Tech & Science

CISA Adds Five Actively Exploited Vulnerabilities to Federal Patching Mandate

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

WASHINGTON — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five actively exploited security flaws to its Known Exploited Vulnerabilities (KEV) catalog on Friday, mandating immediate patching for federal agencies. The update targets critical weaknesses in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS software following confirmed reports of active exploitation in the wild.

The directive, issued on September 12, 2026, requires all federal civilian agencies to remediate these specific vulnerabilities within a strict timeframe. The inclusion in the KEV catalog signals that threat actors are currently leveraging these flaws to compromise networks, necessitating urgent defensive measures across government infrastructure.

Three of the newly listed vulnerabilities affect JFrog Artifactory, a widely used software repository management platform. Attackers have been observed exploiting these flaws to gain unauthorized access to sensitive code repositories and build pipelines. Two additional vulnerabilities were identified in ConnectWise ScreenConnect, a remote support and monitoring tool frequently deployed by managed service providers and IT administrators. Exploitation of these weaknesses allows malicious actors to establish remote control over targeted systems.

The fifth vulnerability impacts MikroTik RouterOS, the operating system used on networking hardware from the Latvian manufacturer. This flaw presents a significant risk to network perimeters, as it can enable attackers to intercept traffic or take control of routing infrastructure. The addition of these router vulnerabilities to the KEV catalog underscores the expanding scope of threats targeting essential network components.

CISA officials stated that the decision to list these flaws was driven by verified evidence of active exploitation. By placing them in the KEV catalog, the agency triggers a mandatory patching requirement for federal entities under existing cybersecurity directives. Agencies failing to address these vulnerabilities risk non-compliance with federal security standards and increased exposure to cyberattacks.

The move comes as part of a broader effort to harden federal networks against evolving threats. The specific technical details of the exploits were not disclosed in the initial announcement, though CISA typically provides detailed guidance on remediation steps alongside KEV updates. Federal agencies are expected to prioritize scanning their environments for affected versions of JFrog, ConnectWise, and MikroTik products immediately.

While the federal mandate is clear, the impact extends beyond government networks. Private sector organizations utilizing these software packages face similar risks, as threat actors often target the same vulnerabilities across both public and private sectors. Industry observers note that the speed at which these flaws were moved to the KEV catalog reflects an accelerated response to active campaigns.

Questions remain regarding the full extent of the exploitation campaigns and whether other critical infrastructure sectors have already been compromised. CISA continues to monitor the situation for new variants or additional vulnerabilities within the same software families. As agencies begin remediation efforts, the agency will likely issue further guidance on detection signatures and mitigation strategies to ensure comprehensive defense against these active threats.

Discussion

0 / 2000