US cyber officials added six actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalog this week, topped by a ConnectWise ScreenConnect flaw that hits the remote-support software hospitals and their IT providers lean on.
The ScreenConnect bug, tracked as CVE-2026-84869, is an improper privilege management and missing authorization flaw. The product is a fixture in clinical IT and at managed service providers, and an earlier ScreenConnect authentication bypass was used by the Black Basta ransomware crew against healthcare targets in 2024.
The rest of the batch spans tooling that shows up across health technology supply chains. JFrog Artifactory carries CVE-2026-42016 (incorrect authorization) and CVE-2026-42018 (improper authentication); attackers have chained them to seize administrative control and plant malicious plugins and backdoors, sometimes just days after patches shipped. MikroTik RouterOS adds CVE-2026-67277 and CVE-2026-86060, and GitLab Community and Enterprise Edition adds a path traversal flaw, CVE-2026-85706.
For healthcare, ScreenConnect is the urgent one. Organizations should confirm which remote-support agents reach clinical networks, check them against the KEV entries, patch immediately, and then hunt for unauthorized access left behind by exploitation.