type: cve ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [cve, kev, remote-support, msp, supply-chain] ยท confidence: medium ยท severity: high ยท affected_sectors: [global] ยท au_impact: false
CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on 11 September on evidence of active exploitation: CVE-2026-42016 (JFrog Artifactory incorrect authorization), CVE-2026-42018 (JFrog Artifactory improper authentication) and CVE-2026-84869 (ConnectWise ScreenConnect improper privilege management and missing authorization).
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-84869 |
| CVSS | Not published in the cited sources |
| Vendor / product | ConnectWise โ ScreenConnect |
| Reported | 2026-09-12 |