CISA Adds Three Known Exploited Vulnerabilities to Catalog
Summary
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-42016 and CVE-2026-42018 for JFrog Artifactory, and CVE-2026-84869 for ConnectWise ScreenConnect. These additions are based on evidence of active exploitation, highlighting their significant risk and the need for prompt remediation.
IFF Assessment
The addition of new, actively exploited vulnerabilities to CISA's KEV catalog indicates increased threats and risks for defenders, requiring them to prioritize patching and mitigation efforts.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should immediately review and prioritize patching for CVE-2026-42016, CVE-2026-42018 (JFrog Artifactory), and CVE-2026-84869 (ConnectWise ScreenConnect) as they have been added to CISA's KEV catalog due to active exploitation. This directive reinforces the need for robust vulnerability management programs, particularly for publicly exposed assets, to mitigate risks from known and exploited threats.