All posts

GitLab CVE-2026-85706 and ScreenConnect CVE-2026-84869 Hit KEV

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 13, 2026

GitLab CVE-2026-85706 exploited one day after disclosure

The headline this weekend is GitLab. CVE-2026-85706 is a path traversal flaw in GitLab Community Edition and Enterprise Edition carrying a CVSS score of 10. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, and SecurityWeek reports it was exploited just one day after disclosure. GitLab is urging users to patch immediately.

If you self-host GitLab, this is a patch-now item, not a patch-eventually item. A max severity path traversal on a source code platform is exactly the kind of foothold that leads to credential theft and supply chain compromise. Confirm your instance version and apply the fixed release before you do anything else this week.

Three more actively exploited CVEs added to KEV

Alongside GitLab, CISA added three more flaws to the KEV catalog on September 11. All four are now confirmed exploited in the wild.

None of these four are flagged ransomware-linked in the current data, but KEV membership means active exploitation is confirmed. Patch on the KEV timeline, not your normal cadence.

  • CVE-2026-84869 in ConnectWise ScreenConnect, an improper privilege management and missing authorization flaw at CVSS 9.9. ScreenConnect is a remote access tool, so an authorization bypass here is a direct route to managed endpoints.
  • CVE-2026-42016 in JFrog Artifactory, an incorrect authorization vulnerability at CVSS 8.8.
  • CVE-2026-42018 in JFrog Artifactory, an improper authentication vulnerability at CVSS 7.5.

Hot movers already on KEV

Beyond the new adds, several previously listed flaws remain high risk based on exploitation probability and ransomware use. CVE-2026-15409 in SonicWall SMA1000 appliances (CVSS 10, EPSS 0.85) and CVE-2026-41940 in WebPros cPanel and WHM (CVSS 9.8, EPSS 0.99) are both KEV-listed and ransomware-linked. CVE-2026-0257 in Palo Alto Networks PAN-OS (CVSS 9.1, EPSS 0.95) and CVE-2026-59310 in Broadcom VMware vCenter (CVSS 9.8) are also KEV-listed and ransomware-linked.

Cisco Firewall Management Center CVE-2026-20079 continues to rank at the top of exploitation trackers, and Rapid7 notes new Metasploit coverage that includes it. Check Point also patched critical VPN flaws CVE-2026-85102 and CVE-2026-85103 this week, and the Dutch NCSC warns exploitation is imminent. Patch Check Point gateways before that warning becomes an incident.

What the trusted press adds

Help Net Security's week in review covers a Linux rootkit deployed on F5 BIG-IP APM devices and confirmed exploitation of Cisco FMC bugs. SecurityWeek details BlueMoon, an exploit kit chaining recent Chrome and Windows zero-days. Help Net Security also reports AI agents were used to exploit PaperCut flaws and breach 395 organizations.

For Microsoft 365 teams specifically, BleepingComputer covers passkey-themed phishing attacks leading to Microsoft 365 data theft, and The Record notes new features in invoice-scam emails that Microsoft researchers are tracking. Microsoft's own blogs this week focus on detecting AI-assisted executive impersonation and invoice fraud with Defender. On the reliability side, Microsoft fixed Teams and Outlook launch failures on ARM Windows PCs.

Do this first

Prioritize by confirmed exploitation, then by ransomware linkage and exploitation probability.

  • Patch GitLab for CVE-2026-85706 now. It is KEV-listed and exploited a day after disclosure.
  • Patch ConnectWise ScreenConnect (CVE-2026-84869) and JFrog Artifactory (CVE-2026-42016, CVE-2026-42018).
  • Patch Check Point VPN gateways for CVE-2026-85102 and CVE-2026-85103 ahead of imminent exploitation.
  • Review ransomware-linked KEV items on your perimeter: SonicWall SMA1000, cPanel and WHM, PAN-OS, and VMware vCenter.
  • Harden Microsoft 365 against passkey-themed phishing and invoice fraud, and confirm your Windows KEV-linked cumulative updates are applied.

Check your own state

To confirm where your environment stands against these adds, the free Microsoft Patch Tracker from Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily so GitLab, ScreenConnect, and Artifactory show up as they land. Siemserva also offers three free unlimited audits of your Microsoft 365, Intune, Defender, and Entra ID environment if you want to check identity and configuration exposure alongside patch state.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-13.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.