Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
DFIR
Emerging1 src

InfoSec News Nuggets – 09/11/2026

Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 Wiz Research identified active exploitation of three JFrog Artifactory vulnerabilities that attackers are chaining to bypass authentication and gain full administrative control of self-hosted repository servers between August 15 and September 8. One chain combines an authentication flaw that improperly hands out an internal anonymous-user token with a token-scope validation bug that lets attackers swap it for admin-level access, while a separate critical flaw, CVE-2026-82329, offers unauthenticated attackers a direct path to admin privileges via a single crafted request to the registry-join endpoint.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

[CISA] CVE-2026-42018 - Confirmed Exploitation

CVE-2026-42018 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-11 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-11 Asserted: 2026-09-11

·CISA KEV
Read →
Vulnerabilities & Patches
Emerging1 src

cve-2026-42018

Anonymous user token generation exposure in JFrog Artifactory

·CVE Program
Read →

You've reached the end of current stories for this search.