Threat Brief — 2026-09-12 — Four KEV additions hit DevOps and remote-access tools
CISA has added four newly confirmed exploited-in-the-wild vulnerabilities to its KEV catalog in a single batch, spanning GitLab, JFrog Artifactory (two separate flaws), and ConnectWise ScreenConnect. All four enable unauthenticated or low-privilege attackers to escalate to file reads, token theft, or full privilege escalation on enterprise infrastructure. The Chromium V8 out-of-bounds write (CVE-2026-87491KEV) also remains in KEV but saw no new development beyond Microsoft Edge ingesting the upstream patch.
Top items
- GitLab CE/EE path traversal (CVE-2026-85706KEV) — Added to CISA KEV. An unauthenticated attacker can read arbitrary files via path traversal. This is a distinct CVE from the previously reported GitLab CVSS 10 flaw (CVE-2023-2825), which was first reported 2026-09-11. Exploitation is confirmed in the wild. (src: CISA KEV)
- JFrog Artifactory improper authentication (CVE-2026-42018KEV) — Added to CISA KEV. When anonymous access is disabled, an unauthenticated caller can still obtain an internal anonymous-user token, effectively bypassing authentication. Exploitation is confirmed in the wild. This is a separate CVE from the Artifactory flaws chained to deploy a Rust backdoor, first reported 2026-09-01. (src: CISA KEV)
- JFrog Artifactory incorrect authorization (CVE-2026-42016KEV) — Added to CISA KEV. A validation check that inspects token signature/issuer but not the token itself allows privilege escalation. Exploitation is confirmed in the wild. Combined with CVE-2026-42018KEV, these two Artifactory flaws present a chained authentication-bypass-to-privilege-escalation path. (src: CISA KEV)
- ConnectWise ScreenConnect improper privilege management and missing authorization (CVE-2026-84869KEV) — Added to CISA KEV. The dual flaw allows an attacker to gain elevated privileges and bypass authorization checks. Exploitation is confirmed in the wild. ScreenConnect is a high-value remote-access tool frequently targeted for initial access by ransomware operators. (src: CISA KEV)
Themes
KEV batch targets unauthenticated entry points. All four additions exploit missing or broken authentication/authorization at the perimeter — no credentials needed for initial access. Three of the four (GitLab, both JFrog CVEs) affect DevOps infrastructure that often holds source code, build artifacts, and deployment secrets, making post-exploitation impact disproportionately high relative to exploit complexity.
JFrog Artifactory under sustained pressure. With two new KEV entries alongside the previously reported backdoor-deployment campaign, Artifactory is accumulating multiple confirmed-exploited vulnerabilities in a two-week window, suggesting active and systematic targeting of self-hosted instances.
