// CISA KEV
Critical Exploits in the Wild: JFrog, GitLab, Cisco FMC, and ScreenConnect Under Active Attack
By NeoShield AI Threat Desk · Published 2026-09-12 · 4 min read
#CISA KEV#JFrog Artifactory#GitLab#Cisco FMC#ConnectWise ScreenConnect#Qilin Ransomware#CVE-2026-42016#CVE-2026-42018
CISA's KEV catalog expanded with five critical vulnerabilities across JFrog Artifactory, GitLab, Cisco FMC, and ConnectWise ScreenConnect, all actively exploited — including a CVSS 10.0 Cisco flaw tied to Qilin ransomware deployments. Security teams must act immediately.
The most urgent item on the desk today is CVE-2026-20079, a Cisco Firepower Management Center authentication bypass vulnerability carrying a perfect CVSS score of 10.0. Multiple threat actors are actively exploiting this flaw to steal credentials and, in confirmed incidents, deploy Qilin ransomware. FMC is the centralized management plane for Cisco's Firepower next-generation firewall estate, meaning a compromise here does not just affect one device — it hands attackers visibility into your entire perimeter security architecture, policy configurations, and potentially lateral movement paths into managed segments. If your FMC instances are internet-exposed or reachable from untrusted network zones, treat this as an active incident until proven otherwise. Patch immediately, rotate all credentials associated with FMC, and audit recent administrative activity for unauthorized policy changes or new user accounts.
JFrog Artifactory is carrying two simultaneous critical entries in the KEV catalog: CVE-2026-42016, an Incorrect Authorization vulnerability, and CVE-2026-42018, an Improper Authentication vulnerability. Artifactory sits at the heart of software supply chains — it stores build artifacts, container images, and package dependencies. Attackers who compromise an Artifactory instance can tamper with artifacts, inject malicious packages into internal pipelines, or exfiltrate proprietary code and credentials embedded in build configurations. The combination of an authorization flaw and an authentication flaw in the same product at the same time is particularly dangerous, as chaining them may allow unauthenticated actors to escalate to full repository control. Organizations running Artifactory should apply vendor patches without delay, audit repository permissions, review recent download and upload logs for anomalous activity, and verify the integrity of artifacts produced during the exposure window.
CVE-2026-85706 affects GitLab Community Edition and Enterprise Edition and is classified as a path traversal vulnerability. GitLab is another cornerstone of developer infrastructure, hosting source code, CI/CD pipelines, secrets, and deployment keys. Path traversal vulnerabilities in source control platforms have historically been leveraged to read sensitive files outside intended directories — think configuration files, private keys, or environment variable stores. CISA's addition to the KEV catalog confirms this is not theoretical. GitLab administrators should patch to the latest fixed release, review access logs for unusual file path requests, and audit any exposed secrets or tokens that may have been readable through the traversal vector.
Rounding out today's alerts is CVE-2026-84869 in ConnectWise ScreenConnect, flagged for Improper Privilege Management and Missing Authorization. ScreenConnect is a widely deployed remote access and support tool, and vulnerabilities in this category of software are perennial favorites for ransomware operators and initial access brokers. A privilege management flaw in a remote access platform can allow attackers to escalate from a low-privileged session to full system control, or to pivot across endpoints being managed through the platform. This is not the first time ScreenConnect has appeared in CISA's KEV catalog, and defenders should treat any unpatched instance as a high-priority exposure.
Defensive priorities for today:
- Patch Cisco FMC immediately for CVE-2026-20079 and isolate FMC management interfaces from untrusted networks using strict firewall rules and jump-host access controls.
- Rotate all credentials, API tokens, and service accounts associated with FMC, JFrog Artifactory, GitLab, and ConnectWise ScreenConnect regardless of whether compromise is confirmed.
- Apply JFrog Artifactory patches for CVE-2026-42016 and CVE-2026-42018, then audit artifact integrity and repository access logs going back at least 30 days.
- Patch GitLab for CVE-2026-85706 and search web access logs for path traversal patterns such as directory traversal sequences in request URIs.
- Update ConnectWise ScreenConnect for CVE-2026-84869 and review session logs for privilege escalation events or sessions initiated outside normal business hours.
- Enable alerting on new administrative account creation and policy changes across all four platforms.
- If Qilin ransomware indicators are relevant to your environment, engage your threat intelligence feed and ensure endpoint detection coverage is current.
The pattern across all five vulnerabilities is consistent: attackers are targeting the infrastructure that builds, manages, and secures everything else. Compromising a firewall manager, an artifact repository, a source control platform, or a remote access tool is not an endpoint compromise — it is a force multiplier that can cascade across an entire organization. Prioritize accordingly.
This briefing is informational and does not substitute for official vendor advisories and patches from Cisco, JFrog, GitLab, and ConnectWise.
Related articles
KEV Surge: Artifactory, ScreenConnect, GitLab, and RouterOS Under Active Attack
CISA has added eight vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, GitLab, and MikroTik RouterOS to its…
CISA KEVCISA KEV Surge: Artifactory, ScreenConnect, GitLab & RouterOS Under Active Attack
CISA added eight vulnerabilities across JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, and GitLab to its Known…
CISA KEVCISA KEV Surge: Six Critical Exploited Flaws Targeting AI, DevOps, and Comms Infrastructure
CISA has added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning AI gateway…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.