HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Auth & Privilege Flaws in GitLab, JFrog Artifactory, and ConnectWise ScreenConnect Added to CISA KEV Catalog

CISA has listed four high‑severity vulnerabilities affecting GitLab, JFrog Artifactory, and ConnectWise ScreenConnect in its KEV catalog. Active exploitation can lead to unauthorized data access and admin control, underscoring the need for continuous third‑party risk monitoring and audit‑ready evidence.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Critical Auth & Privilege Flaws in GitLab, JFrog Artifactory, and ConnectWise ScreenConnect (CVE‑2026‑85706, CVE‑2026‑42016, CVE‑2026‑42018, CVE‑2026‑84869) Added to CISA KEV Catalog

What It Is — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four high‑severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The flaws affect GitLab CE/EE (path traversal), JFrog Artifactory (authorization bypass and token exposure), and ConnectWise ScreenConnect (improper privilege management).

Exploitability — All four have active exploitation in the wild; CVSS scores range from 7.5 to 10.0, with public probing observed within days of disclosure.

Affected Products — GitLab Community & Enterprise Editions, JFrog Artifactory (self‑hosted), ConnectWise ScreenConnect client (versions prior to 26.6.5).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous third‑party risk monitoring; a single vulnerable component can give attackers administrative control over your CI/CD pipeline.
  • Highlights gaps in access‑control and authorization evidence that auditors will scrutinize across multiple frameworks (e.g., NIST CSF, ISO 27001).
  • Provides a concrete trigger for organizations to capture patch‑management and configuration‑state evidence in a Trust Center for audit readiness.

Recommended Actions

  • Apply the vendor‑provided patches immediately (GitLab ≥ 15.11.4, JFrog ≥ 7.73.0, ScreenConnect ≥ 26.6.5).
  • Verify that all third‑party components are inventoried and that their security posture is continuously monitored.
  • Capture and retain evidence of patch deployment, access‑control testing, and configuration baselines for audit purposes.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/199032/security/u-s-cisa-adds-gitlab-jfrog-artifactory-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →