INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitLab Exploitation Vulnerability Found in Known Exploited Vulnerabilities Catalog
| 2026-09-14 14:08 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a list of vulnerabilities to its Known Exploited Vulnerabilities catalog, including the JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 with a CVSS score of 7.5 and the ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability CVE-2026-85706 with a CVSS score of 10.0. These vulnerabilities can allow attackers to bypass authorization checks, escalate privileges, and expose internal anonymous-user tokens, posing significant risks to organizations' security.
Technical Mitigations AI-generated
* Implement secure authentication and authorization: Ensure that all systems, including GitLab, JFrog Artifactory, ConnectWise ScreenConnect, and RouterOS, use strong authentication mechanisms (e.g., multi-factor authentication) and implement robust authorization policies to prevent unauthorized access.
* Regularly update software and firmware: Keep all systems up-to-date with the latest security patches and updates to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Monitor logs for suspicious activity: Regularly review system logs for signs of unusual activity, such as unexpected connections or requests, which could indicate a potential exploit attempt. Implement log analysis tools to identify potential threats in real-time.
* Use secure communication protocols: Ensure that all systems use secure communication protocols (e.g., HTTPS) and consider using encryption when transmitting sensitive data over the network.
* Implement rate limiting and IP blocking: Implement rate limiting on system resources (e.g., CPU, memory) and block suspicious IP addresses to prevent brute-force attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fi•••••.path
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42016CVE-2026-42016
CVE-2026-42018CVE-2026-42018
CVE-2026-67277CVE-2026-67277
CVE-2026-85706CVE-2026-85706
CVE-2026-87719CVE-2026-87719
CVE-2026-82329CVE-2026-82329
CVE-2026-86060CVE-2026-86060
CVE-2026-84869CVE-2026-84869
Target & Sectors
Global Scope
governmentgovernment
technologytechnology
Incident Timeline
2026/09/05
Threat actors exploited vulnerabilities in MikroTik RouterOS to gain unauthorized access and control of devices.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-67277
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
vulnerability
CVE-2026-86060
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
infrastructure
26.6.5
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
attribution
Host
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
attribution
CVE-2026
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
attribution
CERT Polska
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
September 8, 2026
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities catalog.
September 11
Threat actors used a known exploited vulnerability in U.S. CISA's software to target the company on September 11.
Sep 12, 2026
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities catalog.
September 13, 2026
Threat actors exploited RouterOS vulnerabilities in U.S. CISA's Known Exploited Vulnerabilities catalog, prompting federal agencies to patch the flaws by September 13, 2026.
Click on any entity below to view its context and source!
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
September 14, 2026
GitLab and JFrog Artifactory were added to the Known Exploited Vulnerabilities catalog by U.S. CISA due to flaws in their APIs, specifically CVE-2026-85706 affecting ScreenConnect andCVE-2026-84869 affecting ConnectWise's client.
Click on any entity below to view its context and source!
attribution
Known Exploited
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 14, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 14, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.
attribution
GitLab
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 14, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.
CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see.
attribution
ConnectWise ScreenConnect
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 14, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog.
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
organisation
CVE-2026
CVE-2026-42016 can allow attackers to bypass authorization checks and escalate privileges, while CVE-2026-42018 can expose an internal anonymous-user token to unauthenticated attackers.
organisation
CVSS
JFrog Artifactory Incorrect Authorization Vulnerability
CVE-2026-42018
(CVSS score of 7.5)
organisation
JFrog Artifactory
JFrog Artifactory Improper Authentication Vulnerability
CVE-2026-84869
(CVSS score of 9.9) ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
CVE-2026-85706
(CVSS score of 10.0) GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Two of the above vulnerabilities affect JFrog Artifactory.
organisation
ScreenConnect
The vulnerability CVE-2026-84869 affects the ScreenConnect client.
organisation
KeV
The most recent flaw added to the KeV catalog is
CVE-2026-85706
, a path traversal vulnerability in its repository commits API.
organisation
API
The most recent flaw added to the KeV catalog is
CVE-2026-85706
, a path traversal vulnerability in its repository commits API.
organisation
Intel
“
watchTowr
Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request.”
organisation
POST
Defenders should also check logs for suspicious POST requests to GitLab’s repository commit API containing
file.path
parameters, which may indicate exploitation attempts.
infrastructure
18.7
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.1.8
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.2
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.2.6
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.3
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.3.2
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
organisation
VBScript
Huntress researchers
linked
the flaw to several incidents in which malicious VBScript payloads were delivered to newly connected systems.
organisation
ConnectWise
ConnectWise recommends updating to ScreenConnect 26.6.5.
organisation
SSH
A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data.
organisation
CI
A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data.
between August 15 and September 8
Threat actors exploited vulnerabilities in U.S. CISA's Known Exploited Vulnerabilities catalog by targeting self-hosted servers and deploying malicious plugins to gain control.
between August 15 and September 8, 2026
Threat actors used a combination of GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to exploit CVE-2026-82329.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-82329
As
previously reported
by The Hacker News, attackers have been observed chaining the two Artifactory bugs alongside
CVE-2026-82329
(CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.
organisation
The Hacker News
As
previously reported
by The Hacker News, attackers have been observed chaining the two Artifactory bugs alongside
CVE-2026-82329
(CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.
organisation
Artifactory
As
previously reported
by The Hacker News, attackers have been observed chaining the two Artifactory bugs alongside
CVE-2026-82329
(CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.
general_metric
9.8 score
As
previously reported
by The Hacker News, attackers have been observed chaining the two Artifactory bugs alongside
CVE-2026-82329
(CVSS score: 9.8) to take administrator control of self-hosted servers and deploy backdoors between August 15 and September 8, 2026.
2026/09/14
Threat actors used a command vulnerability in MikroTik RouterOS to exploit CVE-2026-84869, which has been linked to a set of three unrelated incidents including the exploitation of CVE-2026-42016 and CVE-2026-86060.
Click on any entity below to view its context and source!
organisation
CVE-2026-42018
CVE-2026-42018
(CVSS score: 7.5) -
organisation
ScreenConnect
"
The exploitation of CVE-2026-84869, on the other hand, has been linked to a set of three unrelated incidents
documented
by Huntress in which threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
organisation
VBScript
"
The exploitation of CVE-2026-84869, on the other hand, has been linked to a set of three unrelated incidents
documented
by Huntress in which threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
organisation
Huntress
"
The exploitation of CVE-2026-84869, on the other hand, has been linked to a set of three unrelated incidents
documented
by Huntress in which threat actors abused ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.
organisation
ConnectWise
ConnectWise has
described
the flaw as a "condition" in the ScreenConnect client that "may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances."
organisation
RouterOS
An improper neutralization of argument delimiters in a command vulnerability in MikroTik RouterOS that could allow an attacker to change the trusted RouterOS policy mask and achieve privilege escalation.
organisation
CVE-2026-67277
CVE-2026-67277
(CVSS score: 8.8) -
organisation
CVE-2026-86060
CVE-2026-86060
(CVSS score: 9.2) -
organisation
MikroTik RouterOS
A missing authentication for a critical function vulnerability in MikroTik RouterOS that could allow kernel memory disclosure and denial-of-service in the btest service.
organisation
Wiz
"Attackers are chaining these vulnerabilities to bypass authentication, escalate privileges, and gain administrative control over vulnerable Artifactory instances," Google-owned Wiz said.
organisation
Groovy
"Observed post-exploitation activity includes the creation of persistent administrator accounts, the deployment of malicious Groovy plugins for code execution, and the installation of Rust-based backdoors to establish persistence.
organisation
MikroTrick
The cybersecurity agency dubbed the exploit chain MikroTrick.
September 25, 2026
Threat actors used a vulnerability in RouterOS to target federal agencies, and CISA ordered the patching of this flaw by September 14, 2026.
Click on any entity below to view its context and source!
attribution
FCEB
Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
attribution
Federal Civilian Executive Branch
Federal Civilian Executive Branch (FCEB) agencies are required to patch the RouterOS flaws by September 13, 2026, the ScreenConnect flaw by September 14, 2026, and the Artifactory flaws by September 25, 2026.
Tactical Metrics
Metrics
infrastructure
18.7
Software Version
Click for context!
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Metrics
infrastructure
19.1.8
Software Version
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Metrics
infrastructure
19.2
Software Version
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Metrics
infrastructure
19.2.6
Software Version
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Metrics
infrastructure
19.3
Software Version
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Metrics
infrastructure
19.3.2
Software Version
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Metrics
infrastructure
26.6.5
Software Version
"Under certain circumstances, this could enable files to be transferred to and executed on the Host client system, including through elevated execution actions," Huntress
said
in an update, urging organizations to update to ScreenConnect version 26.6.5.
CISA's addition of CVE-2026-67277 and CVE-2026-86060
follows a report
from CERT Polska last week in which it said it
observed
unknown threat actors exploiting two flaws in MikroTik RouterOS to seize control of vulnerable devices without authentication.
Intelligence Sources
The Hacker News
2026-09-12
Security Affairs
2026-09-14
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-15T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
24x
organisation
Identified Entity
CVSS
entity
18x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
11x
timeline
Temporal Reference
September 14, 2026
date
8x
vulnerability
Exploited CVE
CVE-2026-42016
cve
7x
infrastructure
Software Version
18.7
version
4x
vulnerability
CVSS Score
8
score
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
general metric
Cisa
1
cisa
2x
general metric
Score
8
score
Contextual Telemetry
Context Block
9 METRICS
general metric
Following Vulnerabilities
2
following vulnerabilities
general metric
Versions
19
versions
general metric
19.2.6
19
19.2.6
tactic
Cyber Operation Type
Privilege Escalation
tactic
general metric
42018 Cvss Score
8
42018 cvss score
general metric
Cvss Score
10
cvss score
general metric
Cve-2026 67277
9
cve-2026 67277
general metric
Cve-2026 86060
9
cve-2026 86060
general metric
Sep
12
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.