Skip to content

Security1 publisher2 min readPublished

Exploitation evidence puts two Artifactory auth flaws and a ScreenConnect privilege bug in KEV

CISA added two JFrog Artifactory access-control flaws and one ConnectWise ScreenConnect privilege flaw to the Known Exploited Vulnerabilities catalog on 11 September, and by the catalog's own criteria published mitigation guidance already exists for each.

The Watch · Security desk

Illustration accompanying Exploitation evidence puts two Artifactory auth flaws and a ScreenConnect privilege bug in KEV

What happened

  • CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on 11 September 2026, in each case on evidence of active exploitation.
  • Two of the entries are JFrog Artifactory flaws: CVE-2026-42016, an incorrect authorization issue, and CVE-2026-42018, an improper authentication issue.
  • The same directive sets expectations for when agencies must check whether attackers compromised the system before the patch went on.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Exploitation is confirmed for all three, so an internet-facing Artifactory or ScreenConnect instance was in an attacker's reach before the catalog entry appeared.
  • decision Federal teams now have to decide how far back to hunt on the same hosts they are patching, and the honest answer is set by log retention.
  • constraint The priority tier is defined by public exposure and post-exploitation control, so each agency has to rank these three against its own asset inventory before it can claim compliance.
  • capability Access-control failures are exercised with protocol-valid requests. Detection lands on application-side authorization logging.

A patch on an authentication flaw closes the path but leaves the question of who walked it earlier. BOD 26-04 puts that second job in writing: the directive establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied [7]. On these two products the look-back is bounded by whatever authorization logging was enabled and how long it was retained.

The weakness titles CISA assigned are access control, three for three: incorrect authorization on CVE-2026-42016, improper authentication on CVE-2026-42018, improper privilege management and missing authorization on CVE-2026-84869 [2][3][4][2]. Exploitation of that class is a run of well-formed requests to a service whose job is answering requests. The evidence sits in application and access logs, and it ages out on the retention schedule.

CISA's bar for adding an entry is a CVE ID, evidence of exploitation, and clear mitigation guidance [9]. All three cleared it. There is something to apply today for each one.

BOD 26-04 binds only Federal Civilian Executive Branch agencies, and CISA encourages every other organisation to adopt risk-based vulnerability management and prioritise KEV items [8]. The directive's top tier is publicly exposed assets that grant total control of the asset post-exploitation, and it allows deferring action on lower-risk vulnerabilities [6]. Whether a given host sits in that tier turns on two things an operator can check without waiting for CISA: is it reachable from the internet, and does exploitation hand over the box. An internal-only Artifactory can legitimately wait behind an exposed ScreenConnect server under the directive's own wording.

Two of the three CVEs are in one product, JFrog Artifactory [1]. That matters for inventory work: one vendor advisory covers two thirds of this batch, and the third needs a separate owner.

CISA did not name an actor, a date of first exploitation, or what exploitation reached beyond the affected host. The argument that these two products are the route to every downstream system therefore rests on where operators put them. The alert confirms exploitation, and the agency wrote that these types of vulnerabilities "are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise" [10][12].

What to watch

  • Whether JFrog or ConnectWise publishes exploitation detail or indicators for CVE-2026-42016, CVE-2026-42018 and CVE-2026-84869.
  • Whether CISA or either vendor describes the two Artifactory flaws as a chain, with one feeding the other.
  • Whether ScreenConnect exploitation shows up in managed downstream estates. That would change the scope from server compromise to fleet compromise.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories