CISA Adds Three Actively Exploited Vulnerabilities (CVE‑2026‑42016, CVE‑2026‑42018, CVE‑2026‑84869) to KEV Catalog
What It Is — CISA announced that three vulnerabilities—two in JFrog Artifactory (incorrect authorization CVE‑2026‑42016 and improper authentication CVE‑2026‑42018) and one in ConnectWise ScreenConnect (improper privilege management CVE‑2026‑84869)—have been added to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation.
Exploitability — All three CVEs are confirmed to be exploited in the wild; CISA’s inclusion in the KEV catalog signals that threat actors are already leveraging them to gain unauthorized control of affected assets.
Affected Products —
- JFrog Artifactory (on‑premises and cloud editions)
- ConnectWise ScreenConnect (remote support platform)
Why It Matters for Trust & Control Assurance
- Vulnerability‑management control – Demonstrates the need for a continuous, risk‑based process that identifies, prioritizes, and remediates known‑exploited flaws, a control objective referenced across NIST CSF 2.0, ISO 27001, and other frameworks.
- Audit‑ready evidence – Timely patching and documented remediation provide defensible proof for auditors that an organization is meeting its due‑diligence obligations.
- Enterprise buyer expectations – Federal and commercial customers increasingly require visible evidence that KEV findings are tracked and closed, making robust control mapping a competitive differentiator.
Recommended Actions
- Inventory your environment for any instances of JFrog Artifactory or ConnectWise ScreenConnect.
- Verify the version numbers against the vendor‑published patches for CVE‑2026‑42016, CVE‑2026‑42018, and CVE‑2026‑84869.
- Apply the patches or implement the recommended mitigations immediately.
- Record the remediation in your vulnerability‑management system and link the activity to the KEV catalog entry for audit traceability.
- Update your risk register to reflect the elevated risk status while remediation is in progress.
Source: CISA Advisory – 11 Sep 2026