U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its 2026-9-14 14:8:2 Author: securityaffairs.com(查看原文) 阅读量:9 收藏

U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini September 14, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2026-42016 (CVSS score of 8.1) JFrog Artifactory Incorrect Authorization Vulnerability 
  • CVE-2026-42018 (CVSS score of 7.5) JFrog Artifactory Improper Authentication Vulnerability 
  • CVE-2026-84869 (CVSS score of 9.9) ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
  • CVE-2026-85706 (CVSS score of 10.0) GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and escalate privileges, while CVE-2026-42018 can expose an internal anonymous-user token to unauthenticated attackers. An attacker can chain the flaws to achieve administrative control.

Attackers have already been seen combining the two Artifactory vulnerabilities with another critical flaw tracked as CVE-2026-82329. The attacks, observed between August 15 and September 8, involved taking control of self-hosted servers, creating persistent administrator accounts, deploying malicious plugins and installing backdoors.

The vulnerability CVE-2026-84869 affects the ScreenConnect client. Under certain conditions, attackers can transfer and execute files through an active remote session without authorization or confirmation from the host. Huntress researchers linked the flaw to several incidents in which malicious VBScript payloads were delivered to newly connected systems. ConnectWise recommends updating to ScreenConnect 26.6.5.

The most recent flaw added to the KeV catalog is CVE-2026-85706, a path traversal vulnerability in its repository commits API.

CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data.

By September 11, active probing and exploitation attempts were already underway. watchTowr researchers are already seeing in-the-wild probes targeting CVE-2026-85706.

watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request.” the company wrote on LinkedIn.

“Organizations with public-facing self-hosted GitLab instances should patch as soon as possible or remove public access.

Defenders should also hunt through log files for HTTP POST requests to “/api/v4/projects/{id}/repository/commits/” URIs containing “file.path” parameters to identify potential exploitation attempts.”

Given how quickly attackers exploit similar GitLab flaws, organizations should patch immediately or remove public access. Defenders should also check logs for suspicious POST requests to GitLab’s repository commit API containing file.path parameters, which may indicate exploitation attempts.

All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected. GitLab assigned the vulnerability a CVSS score of 10.0. The same update cycle also patches CVE-2026-87719, an insecure deserialization flaw that could expose advanced search configuration and credentials, providing an additional reason to upgrade rather than look for narrower workarounds.

The detection query is useful because a file.path parameter in a POST request to the commits API can signal an exploitation attempt.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the GitLab and ConnectWise flaws by September 14, 2026, while the remaining JFrog Artifactory issues must be addressed by September 25, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)




文章来源: https://securityaffairs.com/199032/security/u-s-cisa-adds-gitlab-jfrog-artifactory-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html
如有侵权请联系:admin#unsafe.sh