CISA’s Known Exploited Vulnerabilities catalog just absorbed five flaws with confirmed in-the-wild use, and the one public writeups lead with is CVE-2026-42016, an incorrect-authorization issue in JFrog Artifactory rated 8.1. The rest of the drop lands in ConnectWise ScreenConnect and MikroTik RouterOS. That mix should rearrange your week. A cybersecurity team that still files authorization bugs as configuration debt, and saves emergency change for remote code execution, now has a federal catalog saying those tickets share exploited status.
Five KEV Additions Hit Artifact Repos, Remote Support, and Routers
The catalog update is a coordination problem wearing a patch bulletin. CISA listed five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Those names map to three different owners in a normal shop: the people who run the build cache, the people who remote into broken laptops, and the people who own the edge. They do not share a CAB, a freeze exception, or a logging pipeline.
Federal civilian agencies already live under Binding Operational Directive 22-01. When a CVE hits KEV, CISA sets a remediation due date. Internet-facing entries often get a window measured in weeks. Copy that discipline even if nobody from CISA can fine you. The exploitation evidence is the same whether you are an agency or a 200-person company with one Artifactory VM and a pair of office routers.

Stop waiting for a single CISA patch night. Split the work by plane. Artifact authorization failures leak packages and identity tokens. A remote-support compromise replays an operator on someone else’s desktop. A RouterOS takeover rewrites NAT, forwarding, and management users while your endpoint tools keep staring at workstations. If those three tickets sit in one backlog ranked by CVSS, the router will lose to whatever scored higher and looks more like a textbook exploit.
Name the owners in writing before you argue about change windows. Build systems, help-desk consoles, and edge firmware fail in different ways, and they fail on different calendars. A shared KEV publication date is not a shared maintenance event.
CVE-2026-42016 Treats Broken Authorization as Active Exploitation
CVE-2026-42016 is the tell. Public reporting describes an incorrect authorization flaw, CVSS 8.1, already used in the wild. That is a permissions bug with a CVE number and a KEV row. You will not get a tidy IDS hit for heap spray in Artifactory. You will get an authenticated client asking for an object the ACL should have denied, and a 200 OK.
Most threat detection stacks still earn their keep on malware, brute-force lockouts, and exploit primitives. Authorization failures look like ordinary API traffic on a port your firewall has allowed for years. Threat-protection products that decrypt and score payloads can still grade a legitimate token plus a wrong repository as business as usual. Tune for that, or you will patch after someone has already walked the artifact tree.
ScreenConnect and RouterOS in the same drop should kill the leftover habit of treating appliance and remote-support logic bugs as security hardening chores for next quarter. Once CISA stamps exploited, incident response starts in parallel with the change ticket. Assume the management identity was used. Pull configs. Pull session lists. Pull authz reports. Then patch.
The real problem here is triage theater. Teams still sort by vendor severity because scanners emit it and executives recognize it. KEV is a smaller, meaner list: CISA is willing to say this one is being used. An 8.1 incorrect-authorization CVE on that list outranks a 9.8 that nobody has touched. Your cyber security program should say that out loud in the ticket, or the authz work will slip behind a flashier RCE that is still theoretical in your environment.
Containment Steps for a Mixed-Class KEV Drop
You cannot patch three vendors with one narrative. You can run one intake process and three containments. Open the KEV entries, grab the CVE IDs and CISA due dates, and refuse to merge them into a single “infrastructure patch” story for the weekly CAB.
- Map each new KEV CVE to an owner, WAN versus internal exposure, and a same-day compensation control if the vendor fix will miss the first night.
- On Artifactory, export permission targets, rotate deploy tokens and API keys, and review download and upload logs for identities that should not touch production repos.
- On ScreenConnect, enumerate hosts and relays, reset admin sessions, and require phishing-resistant MFA on the management plane.
- On RouterOS, export the user database and filter rules, disable unused services, and move admin off public addresses.
- Open a tracked incident response case per product class and keep it open until you have negative evidence, not until the installer finished.
After the first 24 hours, change how KEV arrives. Pipe the catalog into the emergency-change queue. Leave scanner CVSS for the weekly pile. Security hardening on these planes is reachability and identity: management interfaces off the internet, allowlisted admins, short sessions, and separate credentials from user SSO where the product allows it. Defense in depth for an authz bug is fewer principals who can even send the request.
Rehearse the IR path that does not start with EDR. Authorization and appliance CVEs close with credential revocation, config diff, and a rebuild of the control plane. A malware hunt is extra work you may still want. It is not the definition of done. If your only closure metric is “hosts returned to green,” a RouterOS user you did not delete will still own the next change window.
Cybersecurity Patch Queues Need a Confirmed-Exploited Track
Vendor severity will keep lying to you in a polite way. A 9.8 with no exploitation evidence will outrank an 8.1 that CISA has already watched get used. If your cybersecurity patch queue is a single sorted list, CVE-2026-42016 loses. Split the queue. Track one: KEV and other confirmed-exploited feeds, with calendar due dates you treat like production incidents. Track two: everything else, still scanned, still fixed, never allowed to crowd out track one.

That split also helps when the confirmation comes from a model vendor instead of CISA. Anthropic said users in Houthi-held Yemen tried to develop advanced weapons with its AI systems, including a failed guided-rocket test, and did not field an operational device. You probably do not run a weapons program. You do run staff with API keys and unsanctioned chats. Log sanctioned model use. Bind keys to owners. Put “provider disabled this account for abuse” into the same incident response intake that already owns KEV. Confirmed abuse is the signal. The channel will keep changing.
Make the next KEV drop boring. Named owners for artifact storage, remote support, and routing. Pre-approved emergency changes. A report that shows time-to-containment from catalog publication, not from the first internal argument about whether 8.1 counts as urgent. If you cannot name who patches Artifactory authz tonight, the catalog already told you who the attackers will try.
Sources
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
- Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
