CVE-2026-42016 actively exploited: JFrog Artifactory Incorrect Authorization Vulnerability
CISA added CVE-2026-42016, an incorrect authorization in JFrog Artifactory, to its Known Exploited Vulnerabilities catalogue. It allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Federal agencies must remediate by September 25, 2026.