securityaffairs.com 14 Sept 2026, 14:08 UTC

CISA Flags Artifactory, ScreenConnect and GitLab Flaws Under Attack

CISA Flags Artifactory, ScreenConnect and GitLab Flaws Under Attack

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect and GitLab to its Known Exploited Vulnerabilities (KEV) catalogue. The entries are CVE-2026-42016 (CVSS 8.1), CVE-2026-42018 (7.5), CVE-2026-84869 (9.9) and CVE-2026-85706 (10.0). The two Artifactory flaws can be chained to bypass authorisation, obtain an internal anonymous-user token and gain administrative control.

Wiz said attacks observed between 15 August and 8 September involved taking over self-hosted servers, creating persistent administrator accounts, deploying malicious plugins and installing backdoors.

CVE-2026-84869 affects the ScreenConnect client and, in certain circumstances, permits unauthorised file transfer and execution during an active remote session. Huntress linked the flaw to incidents involving malicious VBScript payloads delivered to newly connected systems; ConnectWise recommends updating to ScreenConnect 26.6.5.

GitLab’s CVE-2026-85706 is a path-traversal flaw in the repository commits API that can expose SSH keys, database credentials, deploy tokens, CI/CD variables and other sensitive files. watchTowr reported in-the-wild probing by 11 September. Affected versions are Community Edition and Enterprise Edition 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

GitLab customers should patch or remove public access and review logs for POST requests to `/api/v4/projects/{id}/repository/commits/` containing `file.path` parameters. CISA set 14 September 2026 as the deadline for federal agencies to address the GitLab and ScreenConnect flaws, and 25 September 2026 for the Artifactory issues.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline