Critical Auth & Privilege Flaws in GitLab, JFrog Artifactory, and ConnectWise ScreenConnect (CVE‑2026‑85706, CVE‑2026‑42016, CVE‑2026‑42018, CVE‑2026‑84869) Added to CISA KEV Catalog
What It Is — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four high‑severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The flaws affect GitLab CE/EE (path traversal), JFrog Artifactory (authorization bypass and token exposure), and ConnectWise ScreenConnect (improper privilege management).
Exploitability — All four have active exploitation in the wild; CVSS scores range from 7.5 to 10.0, with public probing observed within days of disclosure.
Affected Products — GitLab Community & Enterprise Editions, JFrog Artifactory (self‑hosted), ConnectWise ScreenConnect client (versions prior to 26.6.5).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous third‑party risk monitoring; a single vulnerable component can give attackers administrative control over your CI/CD pipeline.
- Highlights gaps in access‑control and authorization evidence that auditors will scrutinize across multiple frameworks (e.g., NIST CSF, ISO 27001).
- Provides a concrete trigger for organizations to capture patch‑management and configuration‑state evidence in a Trust Center for audit readiness.
Recommended Actions
- Apply the vendor‑provided patches immediately (GitLab ≥ 15.11.4, JFrog ≥ 7.73.0, ScreenConnect ≥ 26.6.5).
- Verify that all third‑party components are inventoried and that their security posture is continuously monitored.
- Capture and retain evidence of patch deployment, access‑control testing, and configuration baselines for audit purposes.
Source: Security Affairs