Activity

Latest CVE events and analysis as they emerge

  1. CVE-2026-85706

    11 Sept 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
    Product
    GitLab Community Edition and Enterprise Edition

    CVE-2026-85706 is a path traversal vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE). This flaw resides within the repository commits API and stems from a combination of improper path confinement and a lack of authentication enforcement. Under specific conditions, an unauthenticated attacker can exploit this vulnerability to read arbitrary files from the affected GitLab server. Successful exploitation of CVE-2026-85706 can lead to the exposure of various sensitive data accessible to the GitLab server process, including configuration details, credentials, secrets, tokens, SSH keys, and database credentials. The vulnerability requires no authentication or user interaction and can be exploited remotely. GitLab released patches for this issue on September 10, 2026, in versions 19.1.8, 19.2.6, and 19.3.2, addressing all affected versions from 18.7 onwards.

  2. CVE-2026-84869

    11 Sept 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
    Product
    ConnectWise ScreenConnect

    CVE-2026-84869 describes a vulnerability found within the ScreenConnect client. This flaw permits the unauthorized transfer and execution of files during an active remote session, bypassing typical authorization or host confirmation processes. It is important to note that this condition specifically affects the ScreenConnect client and does not impact ScreenConnect servers. The vulnerability is associated with improper privilege management and missing authorization.

  3. CVE-2026-42018

    11 Sept 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    JFrog Artifactory Improper Authentication Vulnerability
    Product
    JFrog Artifactory

    CVE-2026-42018 is an improper authentication vulnerability affecting JFrog Artifactory. This flaw allows an unauthenticated caller to obtain an internal anonymous-user token, even when anonymous access is explicitly disabled within the system. The presence of this token could potentially lead to the exposure of sensitive resources within the Artifactory instance. This vulnerability has been observed in active exploitation, often chained with CVE-2026-42016. When combined, these vulnerabilities can enable attackers to escalate privileges and gain administrative control over self-hosted Artifactory servers.

  4. CVE-2026-42016

    11 Sept 2026, 00:00

    Added to CISA KEV catalog

    Vulnerability name
    JFrog Artifactory Incorrect Authorization Vulnerability
    Product
    JFrog Artifactory

    CVE-2026-42016 is a privilege escalation vulnerability affecting JFrog Artifactory Self Hosted versions prior to 7.133.11. The flaw resides in the token validation logic, which correctly verifies the token's signature and issuer but fails to enforce the token's defined scope. This oversight allows an authenticated attacker, even with low-privileged access, to exploit a valid token to perform actions beyond their assigned permissions and escalate their privileges within an Artifactory deployment, potentially reaching administrative access. The vulnerability has been observed in active exploitation, often chained with other Artifactory flaws to bypass authentication and gain administrative control.

  5. CVE-2026-86060

    10 Sept 2026, 00:00

    RouterOS

    Added to CISA KEV catalog

    Vulnerability name
    MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
    Product
    MikroTik RouterOS

    CVE-2026-86060 is an argument-handling flaw identified in MikroTik RouterOS, specifically within its SSH login path. This vulnerability arises when usernames begin with a prohibited character, which can be manipulated to alter the trusted RouterOS policy mask. Such a change ultimately leads to privilege escalation within the system. Exploitation of CVE-2026-86060 requires an unauthenticated SSH session to successfully reach the RouterOS login helper. This flaw is often discussed in conjunction with CVE-2026-67276, an SSH authentication bypass, as chaining these two vulnerabilities can allow an attacker to gain full, unauthenticated control over affected MikroTik devices. MikroTik has released fixes for this issue in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).