U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

CISA added vulnerabilities in GitLab, JFrog Artifactory, and ConnectWise ScreenConnect to its KEV catalog. GitLab's flaw (CVE-2026-85706, CVSS 10.0) allows file access; JFrog's flaws (CVE-2026-42016, CVSS 8.1; CVE-2026-42018, CVSS 7.5) enable privilege escalation; ConnectWise's flaw (CVE-2026-84869, CVSS 9.9) permits unauthorized file execution. Exploits have been observed. Federal agencies must patch by September 14, 2026, for GitLab and ConnectWise, and by September 25, 2026, for JFrog.

Original reporting
Published Sep 14, 2026, 2:16 PM UTC
Analysis
AlphAI AI DeskAI-generated
Added to AlphAI Sep 14, 2026, 5:00 PM UTC. Informational, not investment advice.
How this was made
AlphAI summarizes source reporting and applies a structured AI analysis for relevance, timing, sentiment and ticker impact. Always verify material claims with the original publisher.
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog — source image
Decision brief

The 30-second read

Low
01

Why it matters

The announcement may trigger immediate sell pressure on affected firms as investors reassess exposure and remediation costs.

02

Market read

Security vulnerability disclosures can cause short‑term price moves; traders may consider short positions or hedges.

03

What to watch

Potential for increased sales of security solutions and consulting services to mitigate the vulnerabilities.

Relevance 4/10Novelty 6/10Timing: effective Sep 14 2026

Background

CISA's KEV catalog lists vulnerabilities actively exploited by threat actors; inclusion signals heightened risk and mandatory remediation for U.S. agencies.

Market effects

Increases scrutiny on software supply‑chain security across DevOps tools.

U.S. federal agencies must remediate, potentially driving demand for security services.

Highlights worldwide risk for self‑hosted CI/CD platforms.

Counterpoint

If patches are quickly deployed, the market may view the news as already priced in, limiting downside.

Key entities

  • GitLab Inc.

    Provider of DevOps platform; affected by CVE‑2026‑85706.

  • JFrog Ltd.

    Provider of Artifactory repository manager; affected by two CVEs.

  • ConnectWise

    Private firm; its ScreenConnect product also listed but not publicly traded.

Related articles

$GTLBHighAI 8/10

GitLab Q2 Earnings Call Signals Broad

GitLab (GTLB) reported Q2 revenue of $286.3M, up 21% YoY, and raised full-year guidance. Key highlights include record gross bookings, 42% net ARR growth, and strong first-order activity. Profitability exceeded expectations, with non-GAAP operating income of $42.6M. The company noted AI usage growth and early adoption of its Flex model.

Med

GitLab Patches Critical Flaw Exploited in the Wild

GitLab released a critical patch for a maximum-severity flaw (CVE-2026-85706) in its repository commits API, which is being actively exploited. The vulnerability affects both Community and Enterprise Editions. U.S. authorities have set a remediation deadline for federal agencies. The patch addresses 17 other vulnerabilities, including a critical insecure deserialization flaw (CVE-2026-87719).

MedAI 8/10

GitLab CVE-2026-85706: CVSS 10.0 Flaw Under Attack

GitLab disclosed a critical flaw (CVE-2026-85706) in its repository commits API, scoring a perfect CVSS 10.0. The bug allows unauthenticated attackers to read arbitrary files. GitLab released patches, but active exploitation was observed within 24 hours. CISA added the flaw to its Known Exploited Vulnerabilities catalog, urging immediate action.

High

One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours

GitLab patched a critical path traversal vulnerability (CVE-2026-85706, CVSS 10.0) that allows unauthorized file access. Exploits began hours after disclosure. Affected versions include CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The flaw impacts self-managed instances, with 20,000+ estimated at risk. GitLab.com is patched. The issue highlights structural concerns in GitLab's handling of untrusted file paths.

$GTLBMedAI 8/10

Max severity GitLab path traversal flaw under active reconnaissance

GitLab patched a critical vulnerability (CVE-2026-85706) in its Community and Enterprise Editions, actively exploited in the wild. The flaw, with a CVSS score of 10.0, could allow unauthenticated file access. WatchTowr detected probes and validated exposure. Users of self-managed instances are urged to upgrade. GitLab also fixed another critical flaw (CVE-2026-87719) with a CVSS score of 9.9, enabling unauthorized access to sensitive data.

$FROGMedAI 8/10

JFrog (FROG) Stock Emerges as Top Software Pick Following Strong Customer Conference Feedback

JFrog (FROG) was reaffirmed as a top software pick by TD Cowen after its customer conference, highlighting strong interest in security and governance solutions. The company beat Q2 earnings estimates with EPS of $0.27 and revenue of $163.77M, up 28.7% YoY. 22 analysts rate it Buy with a consensus price target of $107.14. JFrog introduced new security features and AI governance tools. Key clients reported increased usage and spending, driven by AI and security needs.