NoticiasNews

La sesión de soporte remoto como vector de ataque: CISA suma ScreenConnect, Artifactory y RouterOS al catálogo KEVThe Remote Support Session as an Attack Vector: CISA Adds ScreenConnect, Artifactory and RouterOS to the KEV Catalog

2026-09-16

La Agencia de Ciberseguridad y Seguridad de Infraestructura de Estados Unidos (CISA) sumó cinco vulnerabilidades explotadas activamente a su catálogo de Known Exploited Vulnerabilities (KEV), según reportó The Hacker News el 12 de septiembre de 2026. Afectan a JFrog Artifactory, ConnectWise ScreenConnect y MikroTik RouterOS — tres piezas que muchas organizaciones medianas tienen instaladas sin considerarlas parte de su superficie crítica.

Las cinco fallas

  • CVE-2026-84869 (CVSS 9.9) — ConnectWise ScreenConnect: gestión indebida de privilegios y falta de autorización que permite transferir y ejecutar archivos a través de una sesión remota activa sin autorización ni confirmación del anfitrión.
  • CVE-2026-42016 (CVSS 8.1) — JFrog Artifactory: autorización incorrecta que puede derivar en escalación de privilegios, porque se valida la firma y el emisor del token pero no su alcance.
  • CVE-2026-42018 (CVSS 7.5) — JFrog Artifactory: autenticación impropia que puede devolver un token interno de usuario anónimo a un llamador no autenticado incluso con el acceso anónimo deshabilitado.
  • CVE-2026-86060 (CVSS 9.2) — MikroTik RouterOS: neutralización indebida de delimitadores de argumentos que permite alterar la máscara de política confiable y escalar privilegios.
  • CVE-2026-67277 (CVSS 8.8) — MikroTik RouterOS: falta de autenticación en una función crítica, con divulgación de memoria del kernel y denegación de servicio en el servicio btest.

Los plazos de parcheo para agencias federales civiles: RouterOS al 13 de septiembre, ScreenConnect al 14 de septiembre y Artifactory al 25 de septiembre de 2026. Para una empresa privada no son obligatorios, pero funcionan como una excelente vara de urgencia.

Lo que pasa cuando el canal de soporte es el canal de ataque

La falla de ScreenConnect merece leerse dos veces. ConnectWise la describió como una «condición» del cliente que puede permitir que archivos se transfieran y ejecuten a través de una sesión remota activa sin autorización ni confirmación del anfitrión. La empresa aclaró que el problema no afecta a los servidores de ScreenConnect. Huntress amplió: bajo ciertas circunstancias esto puede habilitar la transferencia y ejecución de archivos en el sistema del cliente anfitrión, incluso mediante acciones de ejecución elevada, y recomendó actualizar a la versión 26.6.5.

La explotación de CVE-2026-84869 se vinculó a tres incidentes no relacionados entre sí, documentados por Huntress, en los que actores maliciosos abusaron de ScreenConnect para distribuir una carga útil en VBScript a sistemas recién conectados.

El detalle importante es conceptual. En una mesa de ayuda, la sesión de soporte remoto es el momento de máxima confianza: el usuario acepta que alguien tome el control de su equipo, y precisamente por eso las alertas mentales bajan. Una falla que elimina la confirmación del anfitrión no rompe una barrera técnica menor — rompe el único control humano que quedaba en pie.

Artifactory: la cadena completa

El caso de Artifactory ilustra otro patrón. Según reportes previos, los atacantes encadenaron las dos fallas nuevas junto con CVE-2026-82329 (CVSS 9.8), agregada al KEV a principios de mes, para tomar control administrativo de servidores autogestionados y desplegar puertas traseras entre el 15 de agosto y el 8 de septiembre de 2026.

Wiz, propiedad de Google, describió la actividad posterior a la explotación: creación de cuentas de administrador persistentes, despliegue de plugins maliciosos en Groovy para ejecución de código, e instalación de puertas traseras escritas en Rust para mantener persistencia. Ninguna de esas tres acciones es ruidosa si nadie está mirando el registro de administradores del repositorio.

Las tres preguntas operativas

Más allá de aplicar parches, este lote deja tres preguntas que conviene responder aunque su organización no use ninguno de los tres productos:

  • ¿Quién puede iniciar una sesión remota contra un equipo de la empresa, y queda registrado? No basta con saber qué herramienta está aprobada; hay que saber qué sesiones ocurrieron, con qué cuenta y qué se transfirió durante ellas.
  • ¿Hay inventario de las herramientas de acceso remoto instaladas? Las herramientas de soporte legítimas son el disfraz favorito del atacante moderno, precisamente porque están firmadas, son conocidas y rara vez se bloquean.
  • ¿Cuánto tarda su organización desde que sale un aviso de KEV hasta que confirma que el parche está aplicado? No estimado: medido, con evidencia.

El punto que suele pasarse por alto

Los tres productos de este lote comparten una característica: son infraestructura de soporte, no aplicaciones de negocio. Nadie los presenta en un comité directivo, nadie los incluye en el mapa de sistemas críticos, y por eso suelen quedar fuera del ciclo de parcheo prioritario. Sin embargo, un repositorio de artefactos comprometido contamina cada build posterior, y una herramienta de soporte remoto comprometida llega a cada escritorio que atiende.

La lección práctica es que la criticidad de un sistema no se mide por su cercanía al negocio, sino por su alcance lateral. Y por ese criterio, la mesa de ayuda es uno de los sistemas más críticos de cualquier organización.

En TEKFENIX construimos Servigo365 partiendo de esa idea: cada interacción de soporte queda registrada como un caso con actor identificado, acciones fechadas y evidencia recuperable, de modo que una sesión de asistencia nunca sea un tramo ciego en la historia de un equipo. Y en entornos regulados, CumplimientoControl convierte ese registro en evidencia presentable ante un auditor. Si su organización todavía no puede responder quién accedió remotamente a qué equipo y cuándo, conversemos: esa respuesta es más barata de construir antes del incidente que después.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, as reported by The Hacker News on September 12, 2026. They affect JFrog Artifactory, ConnectWise ScreenConnect and MikroTik RouterOS — three pieces many mid-sized organizations run without considering them part of their critical surface.

The five flaws

  • CVE-2026-84869 (CVSS 9.9) — ConnectWise ScreenConnect: improper privilege management and missing authorization allowing files to be transferred and executed through an active remote session without authorization or host confirmation.
  • CVE-2026-42016 (CVSS 8.1) — JFrog Artifactory: incorrect authorization that can lead to privilege escalation, because the token signature and issuer are validated but not its scope.
  • CVE-2026-42018 (CVSS 7.5) — JFrog Artifactory: improper authentication that can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled.
  • CVE-2026-86060 (CVSS 9.2) — MikroTik RouterOS: improper neutralization of argument delimiters allowing an attacker to change the trusted policy mask and escalate privileges.
  • CVE-2026-67277 (CVSS 8.8) — MikroTik RouterOS: missing authentication for a critical function, with kernel memory disclosure and denial of service in the btest service.

Patch deadlines for federal civilian agencies: RouterOS by September 13, ScreenConnect by September 14, and Artifactory by September 25, 2026. They are not mandatory for private companies, but they work as an excellent urgency benchmark.

What happens when the support channel is the attack channel

The ScreenConnect flaw deserves a second read. ConnectWise described it as a client “condition” that may allow files to be transferred and executed through an active remote session without authorization or host confirmation. The company clarified the issue does not affect ScreenConnect servers. Huntress expanded: under certain circumstances this could enable files to be transferred to and executed on the host client system, including through elevated execution actions, and urged organizations to update to version 26.6.5.

Exploitation of CVE-2026-84869 was linked to three unrelated incidents documented by Huntress, in which threat actors abused ScreenConnect to distribute a VBScript payload to newly connected systems.

The important detail is conceptual. On a help desk, the remote support session is the moment of maximum trust: the user accepts that someone takes control of their machine, and precisely for that reason mental alarms go quiet. A flaw that removes host confirmation does not break a minor technical barrier — it breaks the last human control still standing.

Artifactory: the full chain

The Artifactory case illustrates another pattern. According to prior reporting, attackers chained the two new flaws alongside CVE-2026-82329 (CVSS 9.8), added to KEV earlier this month, to take administrative control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.

Google-owned Wiz described the post-exploitation activity: creation of persistent administrator accounts, deployment of malicious Groovy plugins for code execution, and installation of Rust-based backdoors to establish persistence. None of those three actions is noisy if nobody is watching the repository’s administrator log.

The three operational questions

Beyond applying patches, this batch leaves three questions worth answering even if your organization uses none of the three products:

  • Who can start a remote session against a company machine, and is it logged? Knowing which tool is approved is not enough; you need to know which sessions occurred, under which account, and what was transferred during them.
  • Is there an inventory of installed remote access tools? Legitimate support tools are the modern attacker’s favorite disguise, precisely because they are signed, familiar and rarely blocked.
  • How long does your organization take from a KEV advisory to confirming the patch is applied? Not estimated: measured, with evidence.

The point usually missed

The three products in this batch share a trait: they are support infrastructure, not business applications. Nobody presents them to a board, nobody includes them in the critical systems map, and so they routinely fall outside the priority patching cycle. Yet a compromised artifact repository contaminates every subsequent build, and a compromised remote support tool reaches every desktop it serves.

The practical lesson is that a system’s criticality is not measured by its proximity to the business, but by its lateral reach. And by that criterion, the help desk is one of the most critical systems in any organization.

At TEKFENIX we built Servigo365 on that idea: every support interaction is recorded as a case with an identified actor, timestamped actions and retrievable evidence, so an assistance session is never a blind stretch in a machine’s history. And in regulated environments, CumplimientoControl turns that record into evidence presentable to an auditor. If your organization still cannot answer who accessed which machine remotely and when, let’s talk: that answer is cheaper to build before the incident than after.

← Volver al blog← Back to blog