U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
CISA added vulnerabilities in GitLab, JFrog Artifactory, and ConnectWise ScreenConnect to its KEV catalog. GitLab's flaw (CVE-2026-85706, CVSS 10.0) allows file access; JFrog's flaws (CVE-2026-42016, CVSS 8.1; CVE-2026-42018, CVSS 7.5) enable privilege escalation; ConnectWise's flaw (CVE-2026-84869, CVSS 9.9) permits unauthorized file execution. Exploits have been observed. Federal agencies must patch by September 14, 2026, for GitLab and ConnectWise, and by September 25, 2026, for JFrog.
How this was made

The 30-second read
Why it matters
The announcement may trigger immediate sell pressure on affected firms as investors reassess exposure and remediation costs.
Market read
Security vulnerability disclosures can cause short‑term price moves; traders may consider short positions or hedges.
What to watch
Potential for increased sales of security solutions and consulting services to mitigate the vulnerabilities.
Background
CISA's KEV catalog lists vulnerabilities actively exploited by threat actors; inclusion signals heightened risk and mandatory remediation for U.S. agencies.
Market effects
Increases scrutiny on software supply‑chain security across DevOps tools.
U.S. federal agencies must remediate, potentially driving demand for security services.
Highlights worldwide risk for self‑hosted CI/CD platforms.
Counterpoint
If patches are quickly deployed, the market may view the news as already priced in, limiting downside.
Key entities
- CompanyGitLab Inc.
Provider of DevOps platform; affected by CVE‑2026‑85706.
- CompanyJFrog Ltd.
Provider of Artifactory repository manager; affected by two CVEs.
- CompanyConnectWise
Private firm; its ScreenConnect product also listed but not publicly traded.




