ConnectWise ScreenConnect · JFrog Artifactory · GitLab Community Edition and Enterprise Edition
Date: 2026-09-12 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
CISA added four actively exploited vulnerabilities to the KEV Catalog: ConnectWise ScreenConnect, two JFrog Artifactory flaws, and GitLab CE/EE path traversal. JFrog flaws are being chained to obtain administrator access and deploy backdoors, while GitLab has received in-the-wild probing shortly after disclosure. ScreenConnect and GitLab remediation deadlines are 2026-09-14; prioritize internet-facing instances and investigate suspicious administrative activity.
Critical Vulnerabilities
CVE-2026-84869 — ConnectWise ScreenConnect
- Severity: Not supplied; CISA KEV-listed
- EPSS: Not supplied
- Technical detail: Improper privilege management and missing authorization may allow an attacker to transfer files and execute them through an active remote session without host confirmation. The issue is particularly significant on internet-facing ScreenConnect servers and installations used for privileged remote administration.
- Exploitation status: NEW — actively exploited, added to CISA KEV on 2026-09-11. CISA remediation is due by 2026-09-14.
- Remediation: Apply the vendor security update immediately, restrict administrative access and review ScreenConnect session, file-transfer, process-execution and account-creation logs. Treat unexplained remote-session activity as a potential compromise.
CVE-2026-42016 — JFrog Artifactory
- Severity: Not supplied; CISA KEV-listed
- EPSS: Not supplied
- Technical detail: Incorrect authorization permits privilege escalation because token validation checks the signature and issuer but not the token scope. Attackers can potentially obtain unauthorized administrative capabilities in self-hosted Artifactory environments supporting software build and release pipelines.
- Exploitation status: NEW — actively exploited, added to CISA KEV on 2026-09-11. Reporting indicates this flaw has been chained with CVE-2026-42018 to gain administrative control and deploy backdoors.
- Remediation: Upgrade Artifactory to the fixed release, invalidate and reissue relevant tokens, review administrator and token activity, and inspect build repositories, plugins and hosts for unauthorized modifications. CISA’s remediation deadline is 2026-09-25.
CVE-2026-42018 — JFrog Artifactory
- Severity: Not supplied; CISA KEV-listed
- EPSS: Not supplied
- Technical detail: An unauthenticated caller may receive an internal anonymous-user token even when anonymous access is disabled. This can expose protected resources and, when combined with CVE-2026-42016, support escalation to administrative control.
- Exploitation status: NEW — actively exploited, added to CISA KEV on 2026-09-11. Attacks observed between 2026-08-15 and 2026-09-08 reportedly deployed a Rust backdoor on vulnerable self-hosted servers.
- Remediation: Apply the vendor fix, disable unnecessary anonymous access, rotate Artifactory credentials and tokens, and hunt for unexpected repositories, users, access tokens, web requests and outbound connections. CISA’s deadline is 2026-09-25.
CVE-2026-85706 — GitLab Community Edition and Enterprise Edition
- Severity: CVSS 10.0
- EPSS: Not supplied
- Technical detail: An unauthenticated path-traversal flaw in the repository commits API may allow arbitrary file reads from the GitLab server. Exposure is highest for internet-accessible GitLab instances; sensitive configuration, credential and runner files may be at risk.
- Exploitation status: NEW — actively exploited, added to CISA KEV on 2026-09-11. In-the-wild probing was reported within hours of public disclosure.
- Remediation: Upgrade to the vendor-fixed release immediately, restrict public access where operationally possible, review API and web logs for traversal attempts, and rotate credentials stored on or accessible from GitLab. CISA’s remediation deadline is 2026-09-14.
CVE-2026-87987 / CVE-2026-87984 — Mistral Vibe
- Severity: CVSS 10.0 / 9.3
- EPSS: Not supplied
- Technical detail: Mistral Vibe contains multiple command-permission and workspace-boundary bypasses. Crafted environment-variable assignments or shell constructs can enable arbitrary code execution, while shell redirection can write files outside the approved workspace. The flaws affect developer environments using the listed vulnerable versions.
- Exploitation status: NEW — no exploitation reported in the supplied data.
- Remediation: Update Mistral Vibe to vendor-fixed versions when available, avoid processing untrusted projects or commands, run the tool with least privilege and isolate it from sensitive files, credentials and production networks. Review local command and file-access logs for unexpected activity.
ONGOING
CVE-2026-67277/CVE-2026-86060(MikroTik RouterOS): actively exploited; patch before the 2026-09-13 deadline and restrict management/btest exposure.CVE-2026-75650(Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file modification.CVE-2026-86218(N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.CVE-2026-81963/CVE-2026-85880(Windows): actively exploited; complete September update deployment.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC remain reported; verify patching and hunt for web shells.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation remains reported; deploy the latest maintenance release before the 2026-09-14 deadline.
European Advisories
WID-SEC-2026-3193 (MikroTik RouterOS): covered in Critical Vulnerabilities and remains subject to urgent remediation for active exploitation.
BSI/CERT-Bund published a new high-severity MongoDB advisory, WID-SEC-2026-3320, describing multiple flaws that may permit bypass of query and access restrictions, unauthorized data or file access, data modification or deletion, and denial of service. Identify affected MongoDB servers, apply vendor updates and restrict database interfaces to trusted networks.
WID-SEC-2026-2808 (JFrog Artifactory): covered in Critical Vulnerabilities. The advisory confirms risks including authentication bypass, privilege escalation, impersonation, information disclosure and data manipulation.
BSI also issued updates for Linux Kernel, GNU libc, Red Hat Enterprise Linux, OpenSSL, FasterXML Jackson, FreeRDP, Apache HTTP Server, Netty, Apache ActiveMQ, Android and related components. These are advisory updates rather than newly described incidents; prioritize internet-facing servers, identity services and systems with elevated privileges. BSI/CERT-Bund advisories
Active Threats and Campaigns
- JFrog Artifactory exploitation — NEW: Attackers are chaining CVE-2026-42016 and CVE-2026-42018 to gain administrator control and deploy Rust backdoors. Prioritize exposure assessment, token rotation and compromise hunting on self-hosted instances.
- GitLab exploitation — NEW: In-the-wild probes targeting CVE-2026-85706 followed public disclosure. Monitor repository API requests for traversal patterns and investigate access to sensitive files.
- PaperCut exploitation — STATUS CHANGE: PaperCut released maintenance versions 26.0.5, 25.0.13 and 24.1.10 replacing earlier emergency patches. Deploy the latest release and continue web-shell and account hunting.
- AI-enabled attack activity — NEW: SANS reported a semi-autonomous coding agent harvesting poorly secured LLM resale gateways and aggregating stolen inference access. Audit exposed AI gateways, API keys, unusual inference usage and unauthorized account creation. SANS ISC
Security News and Context
- ConnectWise ScreenConnect, JFrog Artifactory and GitLab vulnerabilities were added to CISA KEV following active exploitation; deadlines are 2026-09-14 or 2026-09-25 depending on the product. CISA
- Microsoft reported passkey- and single-sign-on-themed phishing campaigns targeting Microsoft 365 accounts and corporate data. Reinforce phishing-resistant authentication and review suspicious consent, session and mailbox activity. BleepingComputer
- The EU Cyber Resilience Act’s first security-reporting obligations have begun, including a 24-hour reporting expectation for certain incidents and vulnerabilities. Heise Security
Recommended Actions
- Patch ScreenConnect and GitLab immediately; prioritize internet-facing systems and meet the 2026-09-14 KEV deadline.
- Patch both JFrog Artifactory vulnerabilities, rotate tokens and investigate unauthorized administrators, repositories and backdoor activity.
- Review GitLab API and web logs for path traversal, arbitrary file reads and suspicious credential access.
- Identify Mistral Vibe deployments and isolate or upgrade vulnerable developer environments.
- Deploy the latest PaperCut maintenance release and continue compromise hunting.
- Patch MikroTik RouterOS before 2026-09-13 and restrict btest and management interfaces.
- Review exposed AI gateways and inference platforms for stolen credentials, abnormal usage and unauthorized tenants.
- Continue remediation of previously reported items: Magento, N-central, Windows, SharePoint and Check Point VPN.