CISA Flags Three Actively Exploited Vulnerabilities in JFrog Artifactory and ConnectWise ScreenConnect, Urges Immediate Remediation

Active Exploitation Confirmed: The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed in-the-wild exploitation of three critical security flaws across JFrog Artifactory and ConnectWise ScreenConnect. Unpatched instances are actively targeted for full administrative takeover.
On September 11, 2026, CISA officially released an urgent security advisory adding three high-impact vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These flaws affect widely deployed DevOps infrastructure and remote management tooling: JFrog Artifactory, the enterprise artifact repository and container registry, and ConnectWise ScreenConnect, the ubiquitous remote support and endpoint access platform.
The additions trigger binding compliance requirements for U.S. federal civilian agencies and serve as an urgent warning for global enterprise IT teams to patch immediately and conduct forensic compromise assessments.
#Vulnerability Breakdown & Matrix
The newly listed flaws represent fundamental failures in access control, identity validation, and privilege boundaries. Attackers exploiting these weaknesses can bypass access controls, hijack user sessions, and gain root or administrator level control over the affected asset.
| Vulnerability Identifier | Affected Software | Vulnerability Type | Impact / Exploitation Vector | CISA Catalog Status |
|---|---|---|---|---|
| CVE-2026-42016 | JFrog Artifactory | Incorrect Authorization | Unauthorized access to internal artifact repositories, code packages, and builds | Active Exploitation Added Sept 11, 2026 |
| CVE-2026-42018 | JFrog Artifactory |

