Jfrog: 2 Actively-Exploited Flaws Added to CISA KEV
Jfrog has seen two of its vulnerabilities confirmed as actively exploited in the wild, leading to their inclusion in CISA's Known Exploited Vulnerabilities catalog.

Key findings
- Two Jfrog vulnerabilities, CVE-2026-42016 and CVE-2026-42018, are now in CISA's KEV catalog.
- Both flaws are confirmed to be under active exploitation by threat actors in the wild.
- Organizations using Jfrog products must prioritize immediate patching and mitigation efforts.
- CISA's KEV listing underscores the urgent need for remediation to prevent potential compromise.
CISA has added two Jfrog vulnerabilities, CVE-2026-42016 and CVE-2026-42018, to its Known Exploited Vulnerabilities (KEV) catalog. This addition signals that both flaws have been confirmed as actively exploited in real-world attacks, elevating their risk profile significantly for organizations utilizing Jfrog products.
The KEV catalog serves as a critical resource for federal agencies and private sector organizations, highlighting vulnerabilities that are actively being leveraged by malicious actors. The presence of a vulnerability in this catalog mandates urgent attention and remediation, as it indicates a direct and immediate threat.
The two specific vulnerabilities added are CVE-2026-42016 and CVE-2026-42018. While specific technical details of the exploitation were not disclosed with the KEV update, their inclusion confirms that threat actors have successfully weaponized these flaws. Neither of these vulnerabilities has been publicly associated with ransomware campaigns at the time of their KEV listing.
For defenders, the immediate priority is to identify any instances of affected Jfrog products within their environments and apply available patches or mitigations without delay. CISA typically provides specific remediation due dates for federal civilian executive branch agencies, and these deadlines should be considered a baseline for all organizations to address these critical security gaps. Proactive patching and continuous monitoring are essential to prevent potential compromise from these actively exploited issues.