GetPentest

Artifactory auth bypasses are now on the exploited list

September 15, 2026. From issue 6 of The Compliance Brief, one story for teams that commission penetration tests.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

Issue 6 of The Compliance Brief went to subscribers on September 15, 2026. One of its 5 stories bears on exploited vulnerabilities and security testing, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: CISA

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalogue on September 11. Two affect JFrog Artifactory, covering incorrect authorization and improper authentication, and one affects ConnectWise ScreenConnect for improper privilege management and missing authorization.

Our take, in short

Artifactory sits between your developers and your customers, so an authorization flaw there is a path to shipping someone else's code under your name. If you self-host it, this is a same-day job rather than a next-sprint job.

Read the full take on traztech.ca

Also in issue 6

Outside exploited vulnerabilities and security testing, but in the same email:

Older: issue 4 All issues on GetPentest Newer: issue 7