CISA Adds Three CVEs to KEV Catalog, Triggering BOD 26-04
Two JFrog Artifactory flaws and one ConnectWise ScreenConnect vulnerability now carry federal remediation deadlines, and the post-compromise forensics obligation that comes with them.
TL;DR
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog on September 11: CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, and CVE-2026-84869 in ConnectWise ScreenConnect. Under Binding Operational Directive 26-04, federal agencies must prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets and, where required, determine whether threat actors compromised systems before patching. The directive applies to FCEB agencies, but contractors using these products should expect federal customers to ask whether they've patched, and whether they checked for signs of prior exploitation.
CISA's September 11 KEV update adds two JFrog Artifactory vulnerabilities and one ConnectWise ScreenConnect vulnerability to the catalog that drives federal remediation requirements under BOD 26-04. The additions aren't advisory. They set the clock.
BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV-listed CVEs on publicly exposed assets. It also establishes "basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied," per CISA's own summary. That second obligation (the forensics piece) is what distinguishes BOD 26-04 from its predecessor and what turns each KEV addition into more than a patch-now bulletin.
JFrog Artifactory is widely used in federal software supply chains as a binary repository manager. An incorrect authorization vulnerability and an improper authentication vulnerability, both now confirmed as actively exploited, sit at the intersection of development infrastructure and production artifact distribution. ConnectWise ScreenConnect, a remote access tool, carries its own exposure profile: if attackers have been exploiting CVE-2026-84869 in the wild, the question isn't just whether the patch is applied. It's whether the access was already used.
For contractors, none of this is directly compulsory. BOD 26-04 binds FCEB agencies, not their vendors. But agencies under directive obligation to verify patch status and triage for prior compromise will turn to the organizations running these products on their behalf. A federal customer asking "have you patched these, and what did you find when you checked for compromise" is not a theoretical conversation after a KEV listing.
CISA encourages all organizations (not just federal agencies) to adopt risk-based vulnerability management and prioritize KEV remediation. For contractors supporting federal environments, the encouragement is closer to a requirement in practice.
Published ·Deep Fathom