CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on 11 September on evidence of active exploitation: CVE-2026-42016 (JFrog Artifactory incorrect authorization), CVE-2026-42018 (JFrog Artifactory improper authentication) and CVE-2026-84869 (ConnectWise ScreenConnect improper privilege management and missing authorization). The two Artifactory entries are the flaws researchers observed being chained against self-hosted Artifactory servers in the wild; ScreenConnect is a remote-support platform widely deployed by managed service providers, which makes it a supply-chain foothold rather than a single-victim risk. The additions land under Binding Operational Directive 26-04, which requires US federal civilian agencies to prioritise remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation, and to check for pre-patch compromise rather than simply patching. For non-US operators the practical signal is the same as the wider week's pattern: repository managers and remote-support agents are now the exploited class, and both have small, well-defined exposure surfaces that can be enumerated quickly.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-12 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-42016, CVE-2026-42018, CVE-2026-84869 |