CISA Flags Actively Exploited Flaws in JFrog Artifactory and ConnectWise ScreenConnect
Three vulnerabilities affecting JFrog Artifactory and ConnectWise ScreenConnect have been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild. These products are widely deployed in enterprise and federal environments, making unpatched instances high-value targets for threat actors. Federal agencies are legally required under BOD 26-04 to remediate KEV-listed vulnerabilities on public-facing assets within mandated timeframes, yet many organizations still lack the processes to act quickly on such advisories. Delayed patching of actively exploited vulnerabilities significantly increases the window of opportunity for attackers to achieve initial access, lateral movement, or data exfiltration. This underscores the critical need for mature, repeatable vulnerability management programs that can respond rapidly to emerging exploitation activity.
Tactical Insight
Immediate actions
- Apply vendor-released patches for CVE-2026-42016, CVE-2026-42018 (JFrog Artifactory), and CVE-2026-84869 (ConnectWise ScreenConnect) immediately.
- Audit all internet-facing deployments of affected products and restrict public exposure where patching cannot be immediately completed.
- Verify your organization's asset inventory to confirm whether vulnerable versions are present in your environment.
Long-term improvements
- Establish a formal emergency patching SLA (e.g., 24–72 hours) specifically for vulnerabilities listed in CISA's KEV Catalog.
- Maintain a continuously updated, authoritative inventory of all software assets, including version numbers, to accelerate triage during active exploitation events.
- Integrate KEV Catalog feeds into your vulnerability management platform to automatically trigger prioritized remediation workflows.
Detection measures
- Deploy continuous vulnerability scanning on all internet-facing and critical internal assets with alerting tuned to KEV-listed CVEs.
- Monitor logs for anomalous activity on JFrog Artifactory and ConnectWise ScreenConnect instances, including unusual authentication attempts or API calls.
- Enable threat intelligence feeds that correlate network traffic and endpoint telemetry with known exploitation indicators for KEV-listed vulnerabilities.