HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Advisory

CISA Adds Three Actively Exploited Vulnerabilities (CVE‑2026‑42016, CVE‑2026‑42018, CVE‑2026‑84869) to KEV Catalog

CISA announced that three vulnerabilities affecting JFrog Artifactory and ConnectWise ScreenConnect are now listed in the Known Exploited Vulnerabilities catalog, confirming active exploitation. Organizations must prioritize patching to satisfy BOD 26‑04 and to maintain audit‑ready evidence of vulnerability management.

LiveThreat™ Intelligence · 📅 September 11, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

CISA Adds Three Actively Exploited Vulnerabilities (CVE‑2026‑42016, CVE‑2026‑42018, CVE‑2026‑84869) to KEV Catalog

What It Is — CISA announced that three vulnerabilities—two in JFrog Artifactory (incorrect authorization CVE‑2026‑42016 and improper authentication CVE‑2026‑42018) and one in ConnectWise ScreenConnect (improper privilege management CVE‑2026‑84869)—have been added to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation.

Exploitability — All three CVEs are confirmed to be exploited in the wild; CISA’s inclusion in the KEV catalog signals that threat actors are already leveraging them to gain unauthorized control of affected assets.

Affected Products

  • JFrog Artifactory (on‑premises and cloud editions)
  • ConnectWise ScreenConnect (remote support platform)

Why It Matters for Trust & Control Assurance

  • Vulnerability‑management control – Demonstrates the need for a continuous, risk‑based process that identifies, prioritizes, and remediates known‑exploited flaws, a control objective referenced across NIST CSF 2.0, ISO 27001, and other frameworks.
  • Audit‑ready evidence – Timely patching and documented remediation provide defensible proof for auditors that an organization is meeting its due‑diligence obligations.
  • Enterprise buyer expectations – Federal and commercial customers increasingly require visible evidence that KEV findings are tracked and closed, making robust control mapping a competitive differentiator.

Recommended Actions

  • Inventory your environment for any instances of JFrog Artifactory or ConnectWise ScreenConnect.
  • Verify the version numbers against the vendor‑published patches for CVE‑2026‑42016, CVE‑2026‑42018, and CVE‑2026‑84869.
  • Apply the patches or implement the recommended mitigations immediately.
  • Record the remediation in your vulnerability‑management system and link the activity to the KEV catalog entry for audit traceability.
  • Update your risk register to reflect the elevated risk status while remediation is in progress.

Source: CISA Advisory – 11 Sep 2026

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →