CriticalCISASep 11, 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability  CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability  CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilia

Why it matters

Exploitation is already occurring or the issue is explicitly prioritized by defenders. Validate exposure before lower-priority patch work.

What defenders should do

Check exposure now; patch or mitigate; hunt for signs of exploitation on affected assets.

Verify at the source

CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at www.cisa.gov →

Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security tools