CISA's list that day
11 September 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in JFrog Artifactory, ConnectWise ScreenConnect and GitLab Community Edition and Enterprise Edition. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-85706Path Traversal | GitLab Community Edition and Enterprise Edition | Patch nowForensic triage required by CISA; Metasploit module | 0.93 | ||
| CVE-2026-84869Improper Privilege Management and Missing Authorization | ConnectWise ScreenConnect | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-42018Improper Authentication | JFrog Artifactory | Patch soon | 0.10 | ||
| CVE-2026-42016Incorrect Authorization | JFrog Artifactory | Patch soon | 0.09 |