Our takeCISA added three vulnerabilities to its KEV catalog: two in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018) and one in ConnectWise ScreenConnect (CVE-2026-84869). All are confirmed exploited in the wild. Patch them now.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA added CVE-2026-42016, CVE-2026-42018 (both JFrog Artifactory) and CVE-2026-84869 (ConnectWise ScreenConnect) to its KEV catalog: all three are confirmed exploited in the wild. Prioritize patching or mitigations if you run these products.
What this means for you — Lean IT orgs:CISA added three vulnerabilities to its known exploited list: two in JFrog Artifactory and one in ConnectWise ScreenConnect. Check whether you use either product and apply the vendor's fixes right away.
What this means for you — MSP:CISA added CVE-2026-42016 and CVE-2026-42018 (JFrog Artifactory) plus CVE-2026-84869 (ConnectWise ScreenConnect) to KEV: all confirmed exploited in the wild. Review every client running these tools and ensure patches or workarounds are applied.
What this means for you — Researcher:CISA added three new entries to the KEV catalog today: CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, and CVE-2026-84869 in ConnectWise ScreenConnect. All are confirmed exploited in the wild.