The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added high-severity vulnerabilities affecting GitLab, JFrog Artifactory, and ConnectWise ScreenConnect to its Known Exploited Vulnerabilities (KEV) catalog. This addition, reported by Security Affairs, signals active, real-world exploitation and mandates immediate remediation for federal agencies, setting a critical benchmark for organizations globally.

The advisory includes specific deadlines for federal Civilian Executive Branch (FCEB) agencies to patch or mitigate the flaws. The most urgent deadline applies to a ConnectWise ScreenConnect vulnerability, which must be addressed by September 24, 2026. Agencies have until October 7 to remediate the GitLab and JFrog flaws.

The vulnerabilities pose a significant risk due to the widespread use of these tools in software development, package management, and remote IT support environments:

  • GitLab: A critical flaw allows an attacker with specific privileges to execute arbitrary code on the server. Successful exploitation could lead to a complete compromise of the GitLab instance, threatening source code, CI/CD pipelines, and development secrets.

  • JFrog Artifactory: Two flaws were added. One enables an attacker to bypass authorization checks, potentially leading to unauthorized data access or manipulation. A second vulnerability could permit remote code execution. Compromise of an artifact repository like Artifactory can have severe supply chain consequences, allowing attackers to inject malicious code into software builds.

  • ConnectWise ScreenConnect: An authentication bypass vulnerability could allow a remote, unauthenticated attacker to gain control of a ScreenConnect server. Since ScreenConnect is frequently used for remote access and management, a compromised server could serve as a gateway for attackers to enter and move laterally within a network.

Inclusion in the CISA KEV catalog is a clear indicator that these vulnerabilities are not merely theoretical but are being actively leveraged by threat actors. The federal remediation deadlines provide a concrete timeline for government agencies, but the advisory serves as a critical warning for all organizations using the affected software.

System administrators and security teams are urged to immediately identify all instances of GitLab, JFrog Artifactory, and ConnectWise ScreenConnect in their environments. Applying the vendor-provided patches is the primary mitigation. If patching is not immediately possible, CISA recommends disconnecting vulnerable systems from public-facing networks and implementing strict access controls as a temporary measure. Verification steps should include checking software versions against the specific CVE details and reviewing logs for indicators of compromise related to unauthorized access attempts on these platforms.


美國網絡安全和基礎設施安全局(CISA)已將影響 GitLab、JFrog Artifactory 及 ConnectWise ScreenConnect 的高嚴重性漏洞,加入其已知被利用漏洞(KEV)目錄。據 Security Affairs 報導,此次新增表明漏洞正被積極地進行實際利用,並要求聯邦機構立即進行修復,為全球組織設立了關鍵的基準。

該公告為聯邦民政行政部門(FCEB)機構設定了具體的最後期限,以修補或緩解這些漏洞。其中最緊迫的期限適用於 ConnectWise ScreenConnect 漏洞,必須於 2026 年 9 月 24 日前處理。機構需在 10 月 7 日前修復 GitLab 及 JFrog 的漏洞。

由於這些工具在軟件開發、套件管理及遠程 IT 支援環境中廣泛使用,這些漏洞構成重大風險:

  • GitLab: 一個嚴重漏洞允許擁有特定權限的攻擊者在伺服器上執行任意代碼。成功利用可能導致 GitLab 實例被完全入侵,威脅源代碼、CI/CD 管線及開發機密。
  • JFrog Artifactory: 新增了兩個漏洞。其中一個使攻擊者能繞過授權檢查,可能導致未經授權的數據訪問或篡改。另一個漏洞可能允許遠程代碼執行。入侵像 Artifactory 這類的軟件庫,可能產生嚴重的供應鏈後果,使攻擊者得以在軟件建構過程中注入惡意代碼。
  • ConnectWise ScreenConnect: 一個身份驗證繞過漏洞可能讓遠程、未經身份驗證的攻擊者取得 ScreenConnect 伺服器的控制權。由於 ScreenConnect 常被用於遠程訪問和管理,被入侵的伺服器可能成為攻擊者進入網絡並進行橫向移動的跳板。

被列入 CISA KEV 目錄,明確表明這些漏洞並非僅停留在理論層面,而是正被威脅行為者積極利用。聯邦修復期限為政府機構提供了具體的時間表,但該公告對所有使用相關軟件的組織而言,都是一個關鍵警告。

系統管理員和安全團隊應立即識別其環境中所有 GitLab、JFrog Artifactory 及 ConnectWise ScreenConnect 的實例。應用供應商提供的修補程式是主要的緩解措施。若無法立即修補,CISA 建議將受影響的系統從公共網絡中斷開,並作為臨時措施實施嚴格的訪問控制。驗證步驟應包括根據具體的漏洞詳情檢查軟件版本,並審查日誌以尋找與這些平台上未經授權訪問嘗試相關的入侵指標。

新聞來源 / Original News Source