Critical Authorization Bypass in JFrog Artifactory (CVE‑2026‑42016) and Related Actively‑Exploited Flaws Added to CISA KEV
What It Is — CISA has placed five vulnerabilities—affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS—in its Known Exploited Vulnerabilities (KEV) catalog. One of the flaws, CVE‑2026‑42016 (CVSS 8.1), is an incorrect‑authorization bug that lets an unauthenticated attacker obtain privileged access to Artifactory repositories.
Exploitability — All five flaws are confirmed to be exploited in the wild; public exploit code and attacker‑controlled payloads have been observed.
Affected Products — JFrog Artifactory (on‑premises and cloud), ConnectWise ScreenConnect (remote‑support client), MikroTik RouterOS (router firmware).
Why It Matters for Trust & Control Assurance
- Access‑control hygiene – An authorization bypass directly violates the control objective of “enforcing least‑privilege access” and undermines audit evidence of proper permission management.
- Third‑party component oversight – The flaws reside in widely‑used supply‑chain products; continuous vendor‑risk monitoring is required to prove due‑diligence to auditors and enterprise buyers.
- Defensible audit trail – Demonstrating that you have logged privileged‑access attempts, applied patches promptly, and can produce evidence of remediation satisfies multiple framework mappings (e.g., NIST CSF 2.0 PR.AC‑1).
Recommended Actions
- Map the finding to the “access‑control” control area in your chosen framework and record the gap.
- Verify patch status on all Artifactory, ScreenConnect, and RouterOS instances; apply vendor patches immediately.
- Enable and centralize logging of authentication and authorization events; alert on anomalous privileged‑access attempts.
- Update third‑party risk registers to reflect the active‑exploitation status and schedule continuous monitoring.
Source: The Hacker News – CISA Adds 5 Actively Exploited Flaws to KEV