Active in-the-wild exploitation has been observed leveraging multiple security flaws in widely used enterprise products, including repository management systems, remote support solutions, and network routing hardware. Threat actors are chaining authentication bypasses, privilege management defects, and memory disclosure flaws to execute unauthorized code, escalate rights, and maintain persistent access. The underlying vulnerabilities span high-severity issues with CVSS scores ranging from 7.5 to 9.9, posing severe risks to organization infrastructure. Successful exploitation enables unauthorized file transfers, kernel memory exposures, full system compromise, and backdoor deployment across targeted environments. Immediate remediation and patched deployments are essential to neutralize persistent operational and security risks across impacted host systems.
CVE-2026-42016: An incorrect authorization vulnerability in Artifactory carries a CVSS score of 8.1. The flaw stems from improper validation checks of token signatures and issuers rather than their scope. Attackers exploiting this flaw can achieve privilege escalation and, when chained with complementary flaws, gain full administrative control over self-hosted server instances.[/subscribe_to_unlock_form]
Active in-the-wild exploitation has been observed leveraging multiple security flaws in widely used enterprise products, including repository management systems, remote support solutions, and network routing hardware. Threat actors are chaining authentication bypasses, privilege management defects, and memory disclosure flaws to execute unauthorized code, escalate rights, and maintain persistent access. The underlying vulnerabilities span high-severity issues with CVSS scores ranging from 7.5 to 9.9, posing severe risks to organization infrastructure. Successful exploitation enables unauthorized file transfers, kernel memory exposures, full system compromise, and backdoor deployment across targeted environments. Immediate remediation and patched deployments are essential to neutralize persistent operational and security risks across impacted host systems.
CVE-2026-42016: An incorrect authorization vulnerability in Artifactory carries a CVSS score of 8.1. The flaw stems from improper validation checks of token signatures and issuers rather than their scope. Attackers exploiting this flaw can achieve privilege escalation and, when chained with complementary flaws, gain full administrative control over self-hosted server instances.[emaillocker id="1283"]
CVE-2026-42018: An improper authentication vulnerability in Artifactory is rated at a CVSS score of 7.5. The defect causes internal anonymous-user tokens to be returned to unauthenticated callers even when anonymous access is explicitly disabled. This exposes sensitive internal resources and allows unauthorized callers to bypass access controls.
CVE-2026-84869: An improper privilege management and missing authorization vulnerability in ScreenConnect holds a critical CVSS score of 9.9. The flaw allows unauthorized file transfer and execution across active remote sessions without host confirmation. Threat actors actively exploit this flaw to deliver malicious scripts and execute payloads with elevated privileges on remote systems.
CVE-2026-67277: A missing authentication vulnerability in RouterOS carries a CVSS score of 8.8 and targets a critical internal service. Exploitation permits remote unauthenticated attackers to trigger kernel memory disclosures and initiate denial-of-service conditions within the network operating system, compromising system availability and stability.
CVE-2026-86060: An improper neutralization of argument delimiters in RouterOS carries a CVSS score of 9.2. The flaw allows command-line manipulation to modify trusted policy masks. Attackers exploiting this flaw can achieve full privilege escalation and gain unauthorized control over affected network routing devices.
Enterprise environments must prioritize immediate patching and system updates to prevent active exploitation chains. Organizations should inspect active remote management sessions, audit API token validations, restrict administrative access to internal infrastructure, and monitor host devices for unauthorized execution scripts or secondary backdoors.
The following reports contain further technical details:
[/emaillocker]