U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
CISA added vulnerabilities in GitLab, JFrog Artifactory, and ConnectWise ScreenConnect to its KEV catalog. GitLab's flaw (CVE-2026-85706, CVSS 10.0) allows file access; JFrog's flaws (CVE-2026-42016, CVSS 8.1; CVE-2026-42018, CVSS 7.5) enable privilege escalation; ConnectWise's flaw (CVE-2026-84869, CVSS 9.9) permits unauthorized file execution. Exploits have been observed. Federal agencies must patch by September 14, 2026, for GitLab and ConnectWise, and by September 25, 2026, for JFrog.





