# CISA adds JFrog, ScreenConnect flaws to KEV

Published: 2026-09-11 · Severity: severe · Sectors: technology, government-national
Canonical: https://vorant.io/reports/1ed203a5-069a-5644-a3f8-566df8444c9e/cisa-adds-jfrog-screenconnect-flaws-to-kev

> CISA added three actively exploited vulnerabilities in JFrog Artifactory and ConnectWise ScreenConnect to its Known Exploited Vulnerabilities catalog, requiring urgent federal remediation.

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed evidence of active exploitation. Two affect JFrog Artifactory: CVE-2026-42016 (incorrect authorization) and CVE-2026-42018 (improper authentication), which could allow attackers to bypass access controls on artifact repositories used in software build and deployment pipelines. The third, CVE-2026-84869, affects ConnectWise ScreenConnect and involves improper privilege management combined with missing authorization checks — a remote support/access tool commonly deployed by MSPs and IT help desks, making it an attractive target for privilege escalation and lateral movement.

Under Binding Operational Directive (BOD 26-04), FCEB agencies must prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control of the asset post-exploitation, and must verify whether systems were compromised prior to patching. While the directive is binding only on federal civilian agencies, CISA recommends all organizations using JFrog Artifactory or ConnectWise ScreenConnect apply available patches immediately and check for signs of prior compromise, given confirmed in-the-wild exploitation.

No specific threat actor, malware family, or technical exploitation details were disclosed in this bulletin. Organizations running affected versions of Artifactory or ScreenConnect should treat these as high-priority patching items, particularly where instances are internet-facing, and review authentication and authorization logs for anomalous access consistent with privilege escalation or authentication bypass.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42016 (KEV), CVE-2026-42018 (KEV), CVE-2026-84869 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1ed203a5-069a-5644-a3f8-566df8444c9e/cisa-adds-jfrog-screenconnect-flaws-to-kev.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
