Your Router Is a Open Door: The KEV Alerts UK Small Businesses Cannot Ignore This Week
Four new critical-severity vulnerabilities in consumer-grade routers landed on the NVD this morning. Six more entries hit CISA’s Known Exploited Vulnerabilities catalogue across two days earlier this week. At least two of those confirmed exploits sit in technology that is almost certainly inside UK small business networks right now.
This is today’s threat briefing. The data is the data. Let’s go through it.
What CISA’s KEV List Actually Means
The Known Exploited Vulnerabilities catalogue is not a watchlist. It is not a “we think this might be bad” register. CISA only adds a vulnerability to KEV when there is confirmed evidence of active exploitation in the wild.
That is the signal that matters. When something lands on KEV, attackers are already using it. The debate about whether to patch is over before it starts.
This week, six vulnerabilities were added across two days: 10 and 11 September 2026. The affected systems include MikroTik RouterOS, ConnectWise ScreenConnect, JFrog Artifactory, and GitLab. CISA set a remediation deadline of 25 September 2026 for federal agencies. For UK small businesses, that deadline is a useful benchmark, not a legal obligation. But the threat is identical.
The Two That Matter Most to Your Business
Not every KEV entry is equally relevant to a 20-person accountancy practice in Leeds or a 12-person logistics firm in Bristol. Two of this week’s entries are.
ConnectWise ScreenConnect is remote access software. It is the tool a significant proportion of UK managed service providers use to access and manage their clients’ systems. When your IT provider “remotes in” to fix something on your computer, there is a reasonable chance they are doing it through ScreenConnect.
The exploited vulnerability (CVE-2026-86060, alongside related flaws) means that if your MSP is running an unpatched version of ScreenConnect, an attacker who compromises that tool does not just access the MSP’s own systems. They can pivot to every client the MSP manages. Your business included.
This is a supply chain risk in its most direct form. The vulnerability is not in your software. It is in the software pointed at you.
MikroTik RouterOS is network routing software widely used in small and medium business environments, partly because MikroTik hardware is substantially cheaper than enterprise alternatives. That price point has made it common in UK SMB networks. CVE-2026-85706 and related flaws in RouterOS are now confirmed as actively exploited.
A compromised router is not a minor inconvenience. It sits between your business and the internet. An attacker with control of your router can intercept traffic, redirect connections, and maintain persistent access without touching any of your computers directly. Standard endpoint security tools will not detect it.
The Four Router CVEs Published Today
Separately from the KEV additions, four new critical vulnerabilities were published on the NVD this morning, all rated CVSS 9.9. All four affect the Totolink A3002MU router, firmware version Hh-B20211125.1046.
The vulnerabilities (CVE-2026-90605 through CVE-2026-90608) are buffer overflow flaws in multiple components of the router’s web management interface. Buffer overflow vulnerabilities allow an attacker to send malformed data that causes the software to execute arbitrary code. All four are remotely exploitable. All four have public proof-of-concept exploit code available.
Totolink is a consumer and small business brand. This firmware version dates to November 2021. If you or your IT provider bought an affordable router in the past few years without paying close attention to the brand, it is worth checking.
These four CVEs are not yet on the KEV list. They were published this morning. Based on the pattern of similar vulnerabilities with public exploit code, the window before active exploitation begins is short.
What Your MSP Should Be Telling You
If your managed service provider has not contacted you this week about the ScreenConnect vulnerabilities, that is a gap worth raising. Not because it necessarily means they have not patched, but because client communication during an active exploitation event is a basic standard of service.
A competent MSP knows what software they run. They know when that software has a confirmed exploit. They patch it and they tell their clients what they did and when.
If you ask your IT provider “have you patched the ConnectWise ScreenConnect vulnerabilities listed on CISA’s KEV this week” and they do not know what you are talking about, you have your answer about the quality of service you are receiving.
This is not about blame. It is about information you need to make decisions.
How This Gives You an Edge
Most of your competitors are not asking their IT providers these questions. Most are not reading threat intelligence briefings. Most will not hear about these vulnerabilities until after something has gone wrong.
The businesses that treat cybersecurity as operational intelligence rather than an annual compliance exercise are the ones that avoid incidents. Avoided incidents do not make headlines. They also do not trigger ICO breach notifications, client disclosure obligations, or insurance premium reviews.
If you supply services to larger organisations, demonstrating that you actively monitor threat intelligence and hold your supply chain accountable is increasingly a procurement differentiator. Cyber Essentials certification is the baseline. Evidence of active threat monitoring is the next level.
Making the Business Case
Three points worth taking to whoever holds the IT budget:
First, the MSP liability question. If your IT provider uses exploited software to access your network, and a breach results, the contractual and liability questions are significant. Knowing what software your MSP uses, and confirming it is patched, is basic due diligence. It costs nothing to ask.
Second, the router visibility gap. Most businesses have no monitoring on their network perimeter. Endpoint detection tools watch computers. They do not watch routers. A compromised router is effectively invisible to standard security tooling. This is a known coverage gap that requires a specific type of attention.
Third, the insurance angle. Cyber insurance underwriters are increasingly asking about patch management practices during renewal. An organisation that can demonstrate it monitors KEV additions and acts on them is a materially lower risk than one that patches on an annual cycle. That difference is reflected in premiums.
What to Do Before Friday
Step one: identify your remote access tool. Ask your IT provider what software they use to remotely access your systems. Get the name and version. If it is ConnectWise ScreenConnect, ask them to confirm in writing that they have applied all patches related to the September 2026 KEV additions.
Step two: audit your routers. Ask your IT provider to identify every router in your network. Note the make, model, and firmware version. If any are MikroTik devices, confirm the RouterOS version and that it has been updated to address the actively exploited vulnerabilities. If any are Totolink A3002MU devices on the November 2021 firmware, escalate that to urgent.
Step three: request a patch confirmation log. A competent MSP should be able to produce a record of when patches were applied to critical systems. If they cannot, that is a capability gap.
Step four: bookmark the CISA KEV catalogue. It is publicly available at cisa.gov. New additions appear within days of confirmed exploitation. Checking it weekly takes three minutes and gives you threat intelligence that most small businesses never see.
Step five: document the conversation. Whatever your IT provider tells you, get it in writing. An email will do. If something goes wrong later, documented assurances from your provider matter for insurance claims and any regulatory conversations.
The data is clear this week. The threats are confirmed. The actions are specific. There is no reason to wait.
Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this with someone who needs to hear it. If you know a business owner who uses an MSP and has never asked what software that MSP runs on their network, send them this episode.