CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, all of which center on access-control weaknesses. Two affect JFrog Artifactory: CVE-2026-42016 (incorrect authorization) and CVE-2026-42018 (improper authentication). The third, CVE-2026-84869, affects ConnectWise ScreenConnect and involves improper privilege management and missing authorization.
These flaw classes matter directly to identity and access security because they let attackers bypass authentication, escalate privileges, or reach resources they shouldn’t. Artifactory holds artifacts and often service credentials, while ScreenConnect provides remote administrative access, making both attractive footholds for lateral movement and credential harvesting. Under BOD 26-04, federal agencies must prioritize rapid remediation of high-risk KEV items on publicly exposed assets.
What to take away: patch these promptly, audit exposure of Artifactory and ScreenConnect instances, and review for signs of unauthorized access or privilege abuse given confirmed in-the-wild exploitation.