Ethical Hacking News
The U.S. CISA has added GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog, highlighting the growing threat landscape in the cybersecurity world. Experts recommend that organizations patch immediately or remove public access to prevent exploitation attempts. Defenders should also check logs for suspicious POST requests to GitLab's repository commit API containing file.path parameters, which may indicate exploitation attempts. The addition of these vulnerabilities to the KEV catalog underscores the need for organizations to prioritize cybersecurity and address vulnerabilities promptly.
Three vulnerabilities, CVE-2026-42016, CVE-2026-42018, and CVE-2026-84869, have been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). CVE-2026-42016 in JFrog Artifactory and CVE-2026-84869 in ConnectWise ScreenConnect can be chained to escalate privileges and transfer files without authorization. CVE-2026-85706 in GitLab's repository commits API allows attackers to access sensitive configuration data, and attackers have already been targeting this vulnerability. Federal agencies have until September 14, 2026, to fix GitLab and ConnectWise flaws, while JFrog Artifactory issues must be addressed by September 25, 2026. Organizations are urged to prioritize cybersecurity, patch vulnerabilities promptly, and monitor logs for suspicious activity.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added three vulnerabilities, namely CVE-2026-42016, CVE-2026-42018, and CVE-2026-84869, to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities affect JFrog Artifactory, GitLab, and ConnectWise ScreenConnect, respectively. The addition of these vulnerabilities to the KEV catalog highlights the growing threat landscape in the cybersecurity world, where attackers are increasingly exploiting vulnerabilities to compromise sensitive information.
The vulnerability CVE-2026-42016, which affects JFrog Artifactory, allows attackers to bypass authorization checks and escalate privileges. This vulnerability can be chained with another critical flaw, CVE-2026-82329, to achieve administrative control. The attackers have already been seen combining the two Artifactory vulnerabilities with the critical flaw, taking control of self-hosted servers, creating persistent administrator accounts, deploying malicious plugins, and installing backdoors.
The vulnerability CVE-2026-84869, which affects ConnectWise ScreenConnect, allows attackers to transfer and execute files through an active remote session without authorization or confirmation from the host. This vulnerability has been linked to several incidents where malicious VBScript payloads were delivered to newly connected systems. ConnectWise recommends updating to ScreenConnect 26.6.5 to patch this vulnerability.
The most recent vulnerability added to the KEV catalog is CVE-2026-85706, a path traversal vulnerability in GitLab's repository commits API. This vulnerability allows attackers to access files they should not see, exposing sensitive configuration data such as SSH keys, database credentials, deploy tokens, and CI/CD variables. By September 11, active probing and exploitation attempts were already underway, with watchTowr researchers observing in-the-wild probes targeting CVE-2026-85706.
The U.S. CISA has ordered federal agencies to fix the GitLab and ConnectWise flaws by September 14, 2026, while the remaining JFrog Artifactory issues must be addressed by September 25, 2026. Experts recommend that private organizations review the catalog and address the vulnerabilities in their infrastructure. The detection query for the GitLab vulnerability is useful because a file.path parameter in a POST request to the commits API can signal an exploitation attempt.
The addition of these vulnerabilities to the KEV catalog highlights the need for organizations to prioritize cybersecurity and address vulnerabilities promptly. As attackers continue to exploit similar vulnerabilities, it is crucial for organizations to patch immediately or remove public access to prevent exploitation attempts. Defenders should also check logs for suspicious POST requests to GitLab's repository commit API containing file.path parameters, which may indicate exploitation attempts.
The U.S. CISA's efforts to address these vulnerabilities demonstrate its commitment to protecting the nation's critical infrastructure. As the threat landscape continues to evolve, it is essential for organizations to stay vigilant and address vulnerabilities promptly to prevent exploitation attempts.
Related Information:
https://www.ethicalhackingnews.com/articles/The-US-CISA-Adds-GitLab-JFrog-Artifactory-and-ConnectWise-ScreenConnect-Flaws-to-its-Known-Exploited-Vulnerabilities-Catalog-A-Threat-to-Cybersecurity-ehn.shtml
https://securityaffairs.com/199032/security/u-s-cisa-adds-gitlab-jfrog-artifactory-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-42016
https://www.cvedetails.com/cve/CVE-2026-42016/
https://nvd.nist.gov/vuln/detail/CVE-2026-42018
https://www.cvedetails.com/cve/CVE-2026-42018/
https://nvd.nist.gov/vuln/detail/CVE-2026-84869
https://www.cvedetails.com/cve/CVE-2026-84869/
https://nvd.nist.gov/vuln/detail/CVE-2026-82329
https://www.cvedetails.com/cve/CVE-2026-82329/
https://nvd.nist.gov/vuln/detail/CVE-2026-85706
https://www.cvedetails.com/cve/CVE-2026-85706/
Published: Mon Sep 14 11:17:30 2026 by llama3.2 3B Q4_K_M