INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GitLab Exploitation Vulnerability Found in Known Exploited Vulnerabilities Catalog

| 2026-09-14 14:08 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a list of vulnerabilities to its Known Exploited Vulnerabilities catalog, including the JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 with a CVSS score of 7.5 and the ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability CVE-2026-85706 with a CVSS score of 10.0. These vulnerabilities can allow attackers to bypass authorization checks, escalate privileges, and expose internal anonymous-user tokens, posing significant risks to organizations' security.
Technical Mitigations AI-generated
* Implement secure authentication and authorization: Ensure that all systems, including GitLab, JFrog Artifactory, ConnectWise ScreenConnect, and RouterOS, use strong authentication mechanisms (e.g., multi-factor authentication) and implement robust authorization policies to prevent unauthorized access. * Regularly update software and firmware: Keep all systems up-to-date with the latest security patches and updates to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Monitor logs for suspicious activity: Regularly review system logs for signs of unusual activity, such as unexpected connections or requests, which could indicate a potential exploit attempt. Implement log analysis tools to identify potential threats in real-time. * Use secure communication protocols: Ensure that all systems use secure communication protocols (e.g., HTTPS) and consider using encryption when transmitting sensitive data over the network. * Implement rate limiting and IP blocking: Implement rate limiting on system resources (e.g., CPU, memory) and block suspicious IP addresses to prevent brute-force attacks.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

fi•••••.path
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-42016CVE-2026-42016 CVE-2026-42018CVE-2026-42018 CVE-2026-67277CVE-2026-67277 CVE-2026-85706CVE-2026-85706 CVE-2026-87719CVE-2026-87719 CVE-2026-82329CVE-2026-82329 CVE-2026-86060CVE-2026-86060 CVE-2026-84869CVE-2026-84869
Target & Sectors
Global Scope governmentgovernment technologytechnology
Incident Timeline
‎2026/09/05
Threat actors exploited vulnerabilities in MikroTik RouterOS to gain unauthorized access and control of devices.
vulnerability CVE-2026-67277
vulnerability CVE-2026-86060
infrastructure 26.6.5
attribution Host
attribution CVE-2026
attribution CERT Polska
‎September 8, 2026
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities catalog.
‎September 11
Threat actors used a known exploited vulnerability in U.S. CISA's software to target the company on September 11.
‎Sep 12, 2026
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect vulnerabilities to its Known Exploited Vulnerabilities catalog.
‎September 13, 2026
Threat actors exploited RouterOS vulnerabilities in U.S. CISA's Known Exploited Vulnerabilities catalog, prompting federal agencies to patch the flaws by September 13, 2026.
attribution FCEB
attribution Federal Civilian Executive Branch
‎September 14, 2026
GitLab and JFrog Artifactory were added to the Known Exploited Vulnerabilities catalog by U.S. CISA due to flaws in their APIs, specifically CVE-2026-85706 affecting ScreenConnect andCVE-2026-84869 affecting ConnectWise's client.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution GitLab
attribution ConnectWise ScreenConnect
attribution FCEB
attribution Federal Civilian Executive Branch
organisation CVE-2026
organisation CVSS
organisation JFrog Artifactory
organisation ScreenConnect
organisation KeV
organisation API
organisation Intel
organisation POST
infrastructure 18.7
infrastructure 19.1.8
infrastructure 19.2
infrastructure 19.2.6
infrastructure 19.3
infrastructure 19.3.2
organisation VBScript
organisation ConnectWise
organisation SSH
organisation CI
‎between August 15 and September 8
Threat actors exploited vulnerabilities in U.S. CISA's Known Exploited Vulnerabilities catalog by targeting self-hosted servers and deploying malicious plugins to gain control.
‎between August 15 and September 8, 2026
Threat actors used a combination of GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to exploit CVE-2026-82329.
vulnerability CVE-2026-82329
organisation The Hacker News
organisation Artifactory
general_metric 9.8 score
‎2026/09/14
Threat actors used a command vulnerability in MikroTik RouterOS to exploit CVE-2026-84869, which has been linked to a set of three unrelated incidents including the exploitation of CVE-2026-42016 and CVE-2026-86060.
organisation CVE-2026-42018
organisation ScreenConnect
organisation VBScript
organisation Huntress
organisation ConnectWise
organisation RouterOS
organisation CVE-2026-67277
organisation CVE-2026-86060
organisation MikroTik RouterOS
organisation Wiz
organisation Groovy
organisation MikroTrick
‎September 25, 2026
Threat actors used a vulnerability in RouterOS to target federal agencies, and CISA ordered the patching of this flaw by September 14, 2026.
attribution FCEB
attribution Federal Civilian Executive Branch
Tactical Metrics
Metrics
infrastructure
‎18.7
Software Version
Metrics
infrastructure
‎19.1.8
Software Version
Metrics
infrastructure
‎19.2
Software Version
Metrics
infrastructure
‎19.2.6
Software Version
Metrics
infrastructure
‎19.3
Software Version
Metrics
infrastructure
‎19.3.2
Software Version
Metrics
infrastructure
‎26.6.5
Software Version