On 11 September CISA listed four vulnerabilities as actively exploited. Two are in JFrog Artifactory, the server where companies keep their packages and artifacts. The other two are in GitLab, rated 10.0, and in ScreenConnect, and for those the deadline is only three days.
- CVE-2026-42016: Artifactory checks the token's signature and issuer but not its scope, allowing privilege escalation. Affects versions before 7.133.11.
- CVE-2026-42018: Artifactory can return the internal anonymous-user token to a caller without login when anonymous access is disabled.
- CVE-2026-85706 in GitLab: arbitrary file read without login. CVE-2026-84869 in ScreenConnect: file transfer and execution without authorisation.
Artifactory is where your software build pulls its packages from. A warehouse everything passes through. If an outsider gets into it, the problem reaches everyone who pulls from the warehouse.
This summer we wrote about Artifactory in a different context: OpenAI's report on the Hugging Face incident. Let's be clear from the start: these two flaws are not that one. No official source links them. The only thing in common is the software.
The token where only the signature is checked
The first Artifactory flaw is one of those that sound minor in the description. The system checks that the token is genuine and who issued it, and stops there. It doesn't ask what it was issued for. The pass to the warehouse also opens the director's office.
The second is nastier, because it hits exactly those who did their homework and disabled anonymous access.
GitLab and ScreenConnect: three days
GitLab at 10.0 is the flaw that, under certain conditions, reads arbitrary files from the server without any login. GitLab released the fix on 10 September, CISA listed it the next day and gave three days.
ScreenConnect is a remote access tool providers use to get into their clients' machines. A flaw in it can, in certain circumstances, mean a file dropped onto someone else's computer through a legitimate session. ConnectWise also gives a temporary measure until you update: remove the TransferFiles permission from the roles.
GitLab and ScreenConnect are for today. Artifactory has a longer deadline, but the warehouse your whole software pulls from is not the place to wait until the last day.