Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
DFIR
Emerging1 src

InfoSec News Nuggets – 09/11/2026

Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Research identified active exploitation of three JFrog Artifactory vulnerabilities that attackers are chaining to bypass authentication and gain full administrative control of self-hosted repository servers between August 15 and September 8. One chain combines an authentication flaw that improperly hands out an internal anonymous-user token with a token-scope validation bug that lets attackers swap it for admin-level access, while a separate critical flaw, CVE-2026-82329, offers unauthenticated attackers a direct path to admin privileges via a single crafted request to the registry-join endpoint.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

[CISA] CVE-2026-42016 - Confirmed Exploitation

CVE-2026-42016 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-11 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-11 Asserted: 2026-09-11

·CISA KEV
Read →

You've reached the end of current stories for this search.