Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [incident, government, supply-chain] ยท confidence: high ยท severity: high ยท affected_sectors: [government] ยท au_impact: true

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on 11 September on evidence of active exploitation: CVE-2026-42016 (JFrog Artifactory incorrect authorization), CVE-2026-42018 (JFrog Artifactory improper authentication) and CVE-2026-84869 (ConnectWise ScreenConnect improper privilege management and missing authorization). The two Artifactory entries are the flaws researchers observed being chained against self-hosted Artifactory servers in the wild; ScreenConnect is a remote-support platform widely deployed by managed service providers, which makes it a supply-chain foothold rather than a single-victim risk. The additions land under Binding Operational Directive 26-04, which requires US federal civilian agencies to prioritise remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation, and to check for pre-patch compromise rather than simply patching. For non-US operators the practical signal is the same as the wider week's pattern: repository managers and remote-support agents are now the exploited class, and both have small, well-defined exposure surfaces that can be enumerated quickly.

Attribute Detail
Sector Government
Date 2026-09-12
Source CISA
Reliability Tier 1
CVEs CVE-2026-42016, CVE-2026-42018, CVE-2026-84869