CISA KEV Catalog Update: JFrog Artifactory and ConnectWise ScreenConnect Actively Exploited Vulnerabilities
First seen Sep 12, 2026 · Updated Sep 12, 2026
CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog affecting JFrog Artifactory and ConnectWise ScreenConnect. These flaws involve improper authentication and authorization controls that could allow attackers to bypass access restrictions and gain unauthorized privileged access. FCEB agencies must remediate under BOD 26-04, and CISA urges all organizations to prioritize patching given confirmed in-the-wild exploitation.
Technical Analysis
CVE-2026-42016 and CVE-2026-42018 affect JFrog Artifactory, involving incorrect authorization and improper authentication respectively, which could allow attackers to bypass access controls and gain unauthorized access to stored artifacts, repositories, or administrative functions. CVE-2026-84869 affects ConnectWise ScreenConnect, involving improper privilege management and missing authorization checks, which could allow low-privileged users or unauthenticated attackers to escalate privileges or perform unauthorized actions on remote-access sessions. These vulnerability classes typically enable attackers to hijack accounts, pivot laterally, or gain full control over affected infrastructure once initial access is achieved. Because Artifactory is widely used as a package/artifact repository in CI/CD pipelines and ScreenConnect is a common remote administration tool, compromise of either could allow attackers to poison build artifacts (including packages or model files consumed by AI agent build pipelines) or gain remote control of hosts running LLM agents, RAG pipelines, or orchestration frameworks, exposing API keys, credentials, and pipeline integrity to further compromise.
Affected Systems
JFrog Artifactory (versions affected by CVE-2026-42016 and CVE-2026-42018 — check JFrog security advisories for specific version ranges); ConnectWise ScreenConnect (versions affected by CVE-2026-84869 — check ConnectWise advisories for specific version ranges)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published in this CISA alert; organizations should monitor JFrog and ConnectWise vendor advisories and CISA KEV catalog entries for updates
Remediation Steps
- 1
Apply vendor patches immediately
Update JFrog Artifactory and ConnectWise ScreenConnect to the latest patched versions addressing CVE-2026-42016, CVE-2026-42018, and CVE-2026-84869 as specified in vendor security advisories.
- 2
Comply with BOD 26-04 timelines
FCEB agencies must remediate these KEV Catalog entries within mandated timeframes and check for evidence of prior compromise before applying patches, per BOD 26-04 guidance.
- 3
Audit authentication and authorization configurations
Review Artifactory and ScreenConnect access controls, user permissions, and session management to identify any unauthorized access or privilege escalation that may have occurred prior to patching.
- 4
Restrict public exposure
Limit internet-facing access to Artifactory and ScreenConnect instances, enforce MFA, and place them behind VPN or zero-trust access controls where possible.
- 5
Rotate credentials and API keys
Given that Artifactory often stores credentials and secrets used by CI/CD and AI agent pipelines, rotate any API keys, tokens, or credentials that may have been exposed.
- 6
Review AI agent pipeline integrity
Organizations using Artifactory to distribute packages or models to AI agent, RAG, or LLM tooling frameworks should verify artifact integrity and audit for unauthorized modifications or supply-chain tampering.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.