we_are_coded.by CODE · The world, decoded
БГ
CISA

Two JFrog Artifactory flaws entered the catalog of exploited vulnerabilities, along with GitLab and ScreenConnect

CISA · event date: 11 September 2026Security

On 11 September CISA listed four vulnerabilities as actively exploited. Two are in JFrog Artifactory, the server where companies keep their packages and artifacts. The other two are in GitLab, rated 10.0, and in ScreenConnect, and for those the deadline is only three days.

In short
  • CVE-2026-42016: Artifactory checks the token's signature and issuer but not its scope, allowing privilege escalation. Affects versions before 7.133.11.
  • CVE-2026-42018: Artifactory can return the internal anonymous-user token to a caller without login when anonymous access is disabled.
  • CVE-2026-85706 in GitLab: arbitrary file read without login. CVE-2026-84869 in ScreenConnect: file transfer and execution without authorisation.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Artifactory is where your software build pulls its packages from. A warehouse everything passes through. If an outsider gets into it, the problem reaches everyone who pulls from the warehouse.

This summer we wrote about Artifactory in a different context: OpenAI's report on the Hugging Face incident. Let's be clear from the start: these two flaws are not that one. No official source links them. The only thing in common is the software.

The facts: on 11 September 2026 CISA added four vulnerabilities to the KEV catalog. CVE-2026-42016 in JFrog Artifactory (self-hosted, versions before 7.133.11) is incorrect authorisation: the token's signature and issuer are checked but not its scope, allowing privilege escalation; JFrog published it on 27 July 2026. CVE-2026-42018 lets Artifactory return the internal anonymous-user token to an unauthenticated caller when anonymous access is disabled; JFrog published it on 12 August with fixes in versions 7.111.20, 7.117.27, 7.125.19, 7.133.28 and 7.146.8. The KEV deadline for both is 25 September. CVE-2026-85706 in GitLab Community Edition and Enterprise Edition is a path traversal in the repository commits API that lets an unauthenticated user read arbitrary files from the server; GitLab rates it CVSS 10.0 and fixed it in versions 19.3.2, 19.2.6 and 19.1.8 on 10 September. CVE-2026-84869 in ConnectWise ScreenConnect may, in certain circumstances, allow files to be transferred and executed through an active remote session without authorisation or host confirmation; ConnectWise rates it 9.9 and fixed it in version 26.6.5 per its bulletin of 8 September. The deadline for GitLab and ScreenConnect is 14 September. Cloud versions of Artifactory and GitLab.com have been patched by the vendors.

The token where only the signature is checked

The first Artifactory flaw is one of those that sound minor in the description. The system checks that the token is genuine and who issued it, and stops there. It doesn't ask what it was issued for. The pass to the warehouse also opens the director's office.

A genuine pass is not yet a pass to every door.

The second is nastier, because it hits exactly those who did their homework and disabled anonymous access.

GitLab and ScreenConnect: three days

GitLab at 10.0 is the flaw that, under certain conditions, reads arbitrary files from the server without any login. GitLab released the fix on 10 September, CISA listed it the next day and gave three days.

ScreenConnect is a remote access tool providers use to get into their clients' machines. A flaw in it can, in certain circumstances, mean a file dropped onto someone else's computer through a legitimate session. ConnectWise also gives a temporary measure until you update: remove the TransferFiles permission from the roles.

GitLab and ScreenConnect are for today. Artifactory has a longer deadline, but the warehouse your whole software pulls from is not the place to wait until the last day.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog (official catalog)→JFrog - Security Advisories (CVE-2026-42016, CVE-2026-42018)→GitLab - Patch Release: GitLab 19.3.2, 19.2.6, 19.1.8, 10.09.2026→ConnectWise - 2026-09-08 ScreenConnect Bulletin
Original: https://wearecoded.com/en/articles/kev-artifactory-gitlab-screenconnect.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news