The U.S This article explores vulnerability jfrog artifactory. . Cybersecurity and Infrastructure Security Agency (CISA) has identified five security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS and has added them to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-42018 (CVSS score: 7.5) - A vulnerability in JFrog Artifactory that could provide unauthorized access by returning an anonymous user token when anonymous access is disabled, potentially exposing sensitive information. CVE-2026-82329 was recently added to CISA's KEV catalog.

"Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence." The exploitation of CVE-2026-84869 has been linked to a set of three unrelated incidents documented by Huntress, where threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. ConnectWise has described the flaw as a "condition" in the ScreenConnect client that "may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances."

The issue does not impact ScreenConnect servers.

"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress said in an update, urging organizations to update to ScreenConnect version 26.6.5.