CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. Two affect JFrog Artifactory: CVE-2026-42016, an incorrect authorization flaw, and CVE-2026-42018, an improper authentication issue. The third, CVE-2026-84869, impacts ConnectWise ScreenConnect and involves improper privilege management combined with missing authorization checks.

Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those granting attackers full control after exploitation. The directive also requires agencies to check whether systems were compromised before patches were applied. CISA is urging all organizations, not just federal agencies, to adopt the same risk-based prioritization for these flaws.

GitLab pushes emergency fix for max-severity path traversal

Separately, GitLab urged self-managed customers to patch immediately against CVE-2026-85706, a maximum-severity path traversal vulnerability in the repository commits API. The bug, reported through GitLab’s HackerOne program by a researcher using the handle s3ntago, stems from improper path confinement and missing authentication enforcement. Unauthenticated attackers can exploit it under certain conditions to read arbitrary data, including credentials and secrets, from vulnerable servers.

Although GitLab has not confirmed exploitation, security firm watchTowr reported observing in-the-wild probes targeting internet-exposed GitLab servers within a day of the patch release. WatchTowr warned that indiscriminate exploitation is likely imminent based on the pattern of prior GitLab vulnerabilities, and recommended defenders hunt for HTTP POST requests to repository commits API endpoints containing suspicious file path parameters.

GitLab also patched a second critical flaw, CVE-2026-87719, an insecure deserialization weakness in the GraphQL subscription serializer affecting GitLab EE. This bug allows authenticated users with Duo Chat access to steal credentials and Advanced Search configuration data.

Both issues are fixed in GitLab Community Edition and Enterprise Edition versions 19.3.2, 19.2.6, and 19.1. GitLab.com is already running patched code, and GitLab Dedicated customers do not need to take action, but self-managed installations should upgrade immediately. GitLab’s platform serves more than 30 million registered users, including over half of Fortune 100 companies.