Executive Summary
CISA has added three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerabilities include two JFrog Artifactory flaws (CVE-2026-42016 and CVE-2026-42018) involving incorrect authorization and improper authentication, plus a ConnectWise ScreenConnect vulnerability (CVE-2026-84869) related to improper privilege management and missing authorization. These vulnerabilities pose significant risks to federal enterprises and are being actively exploited by malicious cyber actors as frequent attack vectors. The addition reinforces CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities that can grant total system control post-exploitation, while encouraging all organizations to adopt risk-based vulnerability management practices.
Why This Matters Now
These actively exploited vulnerabilities in widely-used enterprise software highlight the urgent need for organizations to implement comprehensive vulnerability management programs, as attackers are increasingly targeting authorization and authentication flaws to gain initial access and privilege escalation in corporate environments.
Attack Path Analysis
Attackers exploited authorization and authentication vulnerabilities in JFrog Artifactory and ConnectWise ScreenConnect to gain initial access, escalated privileges through improper authentication mechanisms, moved laterally through connected systems, established command and control channels, exfiltrated sensitive data and source code, and disrupted business operations by compromising critical development and remote access infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of CVE-2026-42016 (JFrog Artifactory Incorrect Authorization) and CVE-2026-84869 (ConnectWise ScreenConnect Improper Privilege Management) on publicly exposed assets to gain unauthorized access
Related CVEs
CVE-2024-42016
CVSS 8.8JFrog Artifactory contains an incorrect authorization vulnerability that allows unauthorized access to repository resources.
Affected Products:
JFrog Artifactory – < 7.84.17
Exploit Status:
exploited in the wildCVE-2024-42018
CVSS 7.7JFrog Artifactory improper authentication vulnerability allows attackers to bypass authentication mechanisms.
Affected Products:
JFrog Artifactory – < 7.84.17
Exploit Status:
exploited in the wildCVE-2024-84869
CVSS 8.4ConnectWise ScreenConnect improper privilege management and missing authorization vulnerability allows privilege escalation.
Affected Products:
ConnectWise ScreenConnect – < 23.9.8
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Valid Accounts
Domain Policy Modification
Impair Defenses: Disable or Modify Tools
Remote Services: Remote Desktop Protocol
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Vulnerability Management
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Program - Vulnerability Management
Control ID: 500.10
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Strong Authentication and Authorization
Control ID: Identity - Advanced
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
JFrog Artifactory and ConnectWise ScreenConnect vulnerabilities directly impact IT infrastructure, requiring immediate remediation of authentication flaws and privilege management issues.
Government Administration
BOD 26-04 mandates federal agencies prioritize these KEV catalog vulnerabilities on publicly exposed assets, requiring rapid remediation and compromise assessment.
Computer Software/Engineering
Software development environments using JFrog Artifactory face critical authentication bypass risks, potentially compromising source code repositories and CI/CD pipelines.
Financial Services
Authentication and authorization vulnerabilities threaten compliance frameworks like PCI DSS, requiring enhanced egress security and zero trust segmentation controls.
Sources
- CISA Adds Three Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- JFrog Security Advisorieshttps://jfrog.com/help/r/jfrog-security-advisoriesVerified
- ConnectWise Security Bulletinshttps://www.connectwise.com/company/trust/security-bulletinsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly reduced the attack blast radius by constraining lateral movement between JFrog Artifactory and ConnectWise ScreenConnect systems through microsegmentation and controlled east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric policies would likely have limited the initial compromise scope by restricting network reachability and isolating vulnerable services from broader infrastructure components.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely have constrained privilege escalation by limiting administrative access scope and preventing unauthorized elevation across segmented development environments.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely have significantly limited lateral movement between Artifactory systems and ScreenConnect infrastructure, reducing the attacker's ability to pivot across cloud environments.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility and control mechanisms would likely have detected and limited unauthorized command channels, reducing the attacker's ability to maintain persistent access across cloud infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely have limited data exfiltration by restricting outbound traffic from Artifactory and ScreenConnect systems, reducing the volume and scope of stolen intellectual property.
While development operations would likely still face disruption, the blast radius would be significantly reduced with isolated repositories and constrained remote access scope limiting organizational impact.
Impact at a Glance
Affected Business Functions
- Software Development Lifecycle
- DevOps CI/CD Pipelines
- Remote Technical Support
- IT Infrastructure Management
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of source code repositories, build artifacts, proprietary software, and remote access credentials for organizations using affected JFrog Artifactory and ConnectWise ScreenConnect instances
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate development infrastructure and limit lateral movement between Artifactory, ScreenConnect, and connected systems
- • Deploy Inline IPS (Suricata) to detect and block exploitation attempts targeting known CVEs like those affecting JFrog Artifactory and ConnectWise ScreenConnect
- • Enable Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from compromised Artifactory repositories and ScreenConnect sessions
- • Establish Multicloud Visibility & Control to monitor anomalous interactions with development tools and detect suspicious automation or repeated malformed requests
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal behavior in development environments and alert on unauthorized remote access tool usage



