CISA KEV Alert 11 Sept 2026, 20:32 UTC

CISA Warns of Actively Exploited JFrog Artifactory Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-42016 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects JFrog Artifactory and is an incorrect authorisation flaw that can enable privilege escalation when the product validates a token’s signature and issuer but not its scope.

The flaw allows an attacker to bypass intended authorisation controls. The available data does not specify the attack vector or required access conditions. CVE-2026-42016 has a CVSS score of 8.1 and is rated High. Patch status is unknown, although JFrog has published security advisory and release information.

Active exploitation has been confirmed, as indicated by the KEV listing. The supplied data does not confirm use in ransomware campaigns. CISA set 25 September 2026 as the remediation deadline.

CISA requires organisations to apply mitigations in accordance with vendor instructions and BOD 26-04 guidance, including its Forensics Triage Requirements. Organisations should follow applicable BOD 26-04 guidance for cloud services or discontinue use if mitigations are unavailable. FCEB agencies are directly affected; all organisations should review their Artifactory exposure, including internet-facing assets, and apply the required remediation.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline