Skip to content

CVE-2026-42018

CVE

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
September 11, 2026
Last Seen
September 28, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLa...

Attackers are exploiting three vulnerabilities in self-hosted JFrog Artifactory to gain administrator access in under five minutes. The vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, allow for authentication bypass and privilege escalation. Attackers can chain these flaws to cr...

On September 11, 2026, CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities include CVE-2026-42016, which has a CVSS score of 8.1. This update foll...

A critical vulnerability in ConfigServer Security & Firewall (CSF), tracked as CVE-2026-65638, was disclosed on September 10, 2026. This flaw affects CSF versions 14.00 through 16.29, allowing unauthenticated remote attackers to execute arbitrary commands via the MESSENGER service. Administrators ar...

Public Exploits

Checking GitHub for proof-of-concept code…