Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [cve, kev, artifactory, supply-chain, devops] ยท confidence: medium ยท severity: high ยท affected_sectors: [global] ยท au_impact: false

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on 11 September on evidence of active exploitation: CVE-2026-42016 (JFrog Artifactory incorrect authorization), CVE-2026-42018 (JFrog Artifactory improper authentication) and CVE-2026-84869 (ConnectWise ScreenConnect improper privilege management and missing authorization).

Attribute Detail
CVE CVE-2026-42018
CVSS Not published in the cited sources
Vendor / product JFrog โ€” Artifactory
Reported 2026-09-12