CareScope Watch/Cybersecurity/September 11, 2026
CISA Adds ConnectWise ScreenConnect Flaw to Exploited Vulnerabilities List
CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The additions include an improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect (CVE-2026-84869), alongside two authorization and authentication flaws in JFrog Artifactory.
Why it matters
CISA warns that these types of vulnerabilities are frequent attack vectors for malicious cyber actors. Because active exploitation has been observed in the wild, exposed systems face immediate risk of compromise. CISA encourages all organizations, not just federal agencies, to adopt risk-based vulnerability management and prioritize patching cataloged flaws.
What it means for your practice
Practices and their managed IT service providers should check immediately whether ConnectWise ScreenConnect or JFrog Artifactory is deployed in their environment. If present, administrators should apply available vendor security updates without delay and review systems to ensure they were not compromised prior to patching.
More from the Watch
Cybersecurity/Sep 10
CISA Warns of Actively Exploited MikroTik RouterOS Vulnerabilities
CISA has added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. The flaws include CVE-2026-67277, a missing authentication vulnerability for a critical function, and CVE-2026-86060, an improper neutralization of argument delimiters in a command.
What it meansCybersecurity/Sep 10
Orthanc DICOM Server Vulnerable to Denial-of-Service Flaw
A vulnerability in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to trigger a heap out-of-bounds write. The issue stems from an integer overflow in pitch and buffer-size computation when decoding an attacker-supplied PNG or JPEG image. Exploitation crashes the Orthanc process, causing a denial-of-service condition.
What it meansCompliance/Sep 4
Information blocking expectations keep tightening
The federal information blocking rules require that patients and their designated recipients get electronic access to their records without unnecessary delay, and enforcement attention has continued to grow rather than fade.
What it means
