Vulnerability

CISA Flags Actively Exploited Flaws in JFrog Artifactory and ConnectWise ScreenConnect

FORTSECURE GLOBAL· 2026-09-13🛰 CISA Cybersecurity Advisories
#Vulnerability#Application Security#Cybersecurity#Incident Response

The Cybersecurity and Infrastructure Security Agency has cataloged three critical security flaws impacting JFrog Artifactory and ConnectWise ScreenConnect due to active in-the-wild exploitation.

Critical Vulnerabilities Added to CISA KEV Catalog\n\nThe Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) Catalog by adding three vulnerabilities currently exploited in active cyber campaigns. The newly listed security flaws involve widely adopted enterprise software: JFrog Artifactory and ConnectWise ScreenConnect.\n\nThe cataloged issues comprise CVE-2026-42016, an incorrect authorization vulnerability in JFrog Artifactory, and CVE-2026-42018, which involves improper authentication in the same platform. In addition, CVE-2026-84869 affects ConnectWise ScreenConnect, stemming from improper privilege management coupled with missing authorization mechanisms. Attackers frequently exploit flaws of this nature to bypass perimeter controls, elevate privileges, and compromise critical software supply chains or remote support infrastructure.\n\n## Strategic Guidance and Mitigation\n\nOrganizations relying on JFrog Artifactory and ConnectWise ScreenConnect should urgently review their deployed instances. FORTSECURE GLOBAL cybersecurity specialists recommend the following immediate actions:\n\n- Apply Vendor Patches: Identify and upgrade all vulnerable installations of Artifactory and ScreenConnect to the latest secure releases provided by the respective vendors.\n- Audit Privilege Models: Ensure that administrative interfaces are not publicly exposed to the internet. Implement robust role-based access control (RBAC) and multifactor authentication (MFA).\n- Continuous Monitoring: Inspect access logs for unusual administrative access or anomalous session spikes that might signify active exploitation.


แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Fri, 11 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Fri, 11 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog