rootpwn

Threat Intel

CISA Expands KEV Catalog with Three New Exploited Vulnerabilities

CISA has added CVE‑2026‑42016, CVE‑2026‑42018, and CVE‑2026‑84869 to its Known Exploited Vulnerabilities catalog after confirmed active exploitation. The flaws affect JFrog Artifactory’s authorization and authentication controls and ConnectWise ScreenConnect’s privilege management, enabling attackers to gain full control of exposed assets. Federal agencies must now prioritize patching these high‑risk CVEs under BOD 26‑04, while the agency urges all organizations to adopt risk‑based remediation and report any other exploited CVEs via the KEV Nomination Form.

In a move to tighten federal cybersecurity, the Cybersecurity and Infrastructure Security Agency (CISA) has added three new CVEs to its Known Exploited Vulnerabilities (KEV) catalog. The additions—CVE‑2026‑42016, CVE‑2026‑42018, and CVE‑2026‑84869—represent confirmed, active exploitation in widely used software.

What’s at Stake?

  • CVE‑2026‑42016: JFrog Artifactory suffers from an incorrect authorization flaw that lets attackers bypass intended access controls.
  • CVE‑2026‑42018: Another JFrog Artifactory issue, this time an improper authentication bug that can grant unauthorized users full system access.
  • CVE‑2026‑84869: ConnectWise ScreenConnect’s privilege management is broken, allowing attackers to elevate privileges and compromise the entire remote‑access platform.
These vulnerabilities are prime targets for malicious actors, especially on publicly exposed assets that grant attackers total control once exploited.

Federal Guidance Under BOD 26‑04

Binding Operational Directive 26‑04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high‑risk KEV-listed CVEs on exposed systems. The directive also mandates agencies check for evidence of compromise before applying patches and sets clear timelines for action. While the directive is specific to federal agencies, CISA encourages all organizations to adopt a risk‑based approach and address KEV catalog vulnerabilities promptly.

What to Do Next

  • Review the three new CVEs and assess whether your environment is affected.
  • Apply patches or mitigations as soon as possible, following the guidance provided by the vendors.
  • Check for signs of exploitation before deploying fixes and keep logs for incident response.
  • If you discover another actively exploited CVE not yet in the catalog, submit it via CISA’s KEV Nomination Form.

By staying ahead of these newly catalogued threats, organizations can reduce the risk of a full system takeover and maintain a stronger security posture.

CISA KEV Vulnerability Management Artifactory ScreenConnect

← All news