rootpwn

Advisories

CISA Expands KEV Catalog with Three Fresh Exploited JFrog and ConnectWise Flaws

CISA has added three new CVEs to its Known Exploited Vulnerabilities catalog, spotlighting serious authorization lapses in JFrog Artifactory and ConnectWise ScreenConnect. The update underscores the agency’s Binding Operational Directive 26‑04, which mandates rapid patching of high‑risk flaws on publicly exposed federal assets. All organizations are urged to adopt risk‑based remediation and can submit unlisted exploited vulnerabilities via CISA’s nomination form.

In a move that tightens the federal cyber‑security posture, the Cybersecurity and Infrastructure Security Agency (CISA) has incorporated three newly discovered, actively exploited vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog. The additions target popular software platforms used across government and industry alike.

New KEV Entries

  • CVE‑2026‑42016 – JFrog Artifactory: Incorrect Authorization, allowing attackers to perform actions beyond their intended scope.
  • CVE‑2026‑42018 – JFrog Artifactory: Improper Authentication, enabling unauthorized access to protected resources.
  • CVE‑2026‑84869 – ConnectWise ScreenConnect: Improper Privilege Management and Missing Authorization, granting attackers full control over exposed assets.

These flaws are especially dangerous because they provide a direct path for malicious actors to seize control of systems that are publicly reachable. The new entries reinforce the growing trend of exploitation focused on authorization weaknesses.

Implications for Federal Agencies

Under Binding Operational Directive (BOD) 26‑04, Federal Civilian Executive Branch (FCEB) agencies must prioritize the remediation of KEV-listed CVEs on publicly exposed assets that could grant total control after exploitation. The directive also requires agencies to verify whether a system has already been compromised before applying a patch, and to defer action on lower‑risk vulnerabilities.

While BOD 26‑04 applies only to FCEB agencies, CISA encourages all organizations—public and private—to adopt a risk‑based vulnerability management approach and to address KEV catalog flaws with urgency.

How to Get a Vulnerability Added

Organizations that discover an actively exploited vulnerability not yet in the KEV catalog can submit it through CISA’s KEV Nomination Form. Submissions must include a CVE identifier, proof of exploitation, and clear mitigation guidance.

CISA will continue to review and add vulnerabilities that meet its criteria, ensuring the catalog remains a dynamic tool for prioritizing defensive efforts.

CISA KEV Vulnerability Management JFrog ConnectWise BOD 26-04

← All news