GitLab CVE-2026-85706 exploited one day after disclosure
The headline this weekend is GitLab. CVE-2026-85706 is a path traversal flaw in GitLab Community Edition and Enterprise Edition carrying a CVSS score of 10. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, and SecurityWeek reports it was exploited just one day after disclosure. GitLab is urging users to patch immediately.
If you self-host GitLab, this is a patch-now item, not a patch-eventually item. A max severity path traversal on a source code platform is exactly the kind of foothold that leads to credential theft and supply chain compromise. Confirm your instance version and apply the fixed release before you do anything else this week.
Three more actively exploited CVEs added to KEV
Alongside GitLab, CISA added three more flaws to the KEV catalog on September 11. All four are now confirmed exploited in the wild.
None of these four are flagged ransomware-linked in the current data, but KEV membership means active exploitation is confirmed. Patch on the KEV timeline, not your normal cadence.
- CVE-2026-84869 in ConnectWise ScreenConnect, an improper privilege management and missing authorization flaw at CVSS 9.9. ScreenConnect is a remote access tool, so an authorization bypass here is a direct route to managed endpoints.
- CVE-2026-42016 in JFrog Artifactory, an incorrect authorization vulnerability at CVSS 8.8.
- CVE-2026-42018 in JFrog Artifactory, an improper authentication vulnerability at CVSS 7.5.
Hot movers already on KEV
Beyond the new adds, several previously listed flaws remain high risk based on exploitation probability and ransomware use. CVE-2026-15409 in SonicWall SMA1000 appliances (CVSS 10, EPSS 0.85) and CVE-2026-41940 in WebPros cPanel and WHM (CVSS 9.8, EPSS 0.99) are both KEV-listed and ransomware-linked. CVE-2026-0257 in Palo Alto Networks PAN-OS (CVSS 9.1, EPSS 0.95) and CVE-2026-59310 in Broadcom VMware vCenter (CVSS 9.8) are also KEV-listed and ransomware-linked.
Cisco Firewall Management Center CVE-2026-20079 continues to rank at the top of exploitation trackers, and Rapid7 notes new Metasploit coverage that includes it. Check Point also patched critical VPN flaws CVE-2026-85102 and CVE-2026-85103 this week, and the Dutch NCSC warns exploitation is imminent. Patch Check Point gateways before that warning becomes an incident.
What the trusted press adds
Help Net Security's week in review covers a Linux rootkit deployed on F5 BIG-IP APM devices and confirmed exploitation of Cisco FMC bugs. SecurityWeek details BlueMoon, an exploit kit chaining recent Chrome and Windows zero-days. Help Net Security also reports AI agents were used to exploit PaperCut flaws and breach 395 organizations.
For Microsoft 365 teams specifically, BleepingComputer covers passkey-themed phishing attacks leading to Microsoft 365 data theft, and The Record notes new features in invoice-scam emails that Microsoft researchers are tracking. Microsoft's own blogs this week focus on detecting AI-assisted executive impersonation and invoice fraud with Defender. On the reliability side, Microsoft fixed Teams and Outlook launch failures on ARM Windows PCs.
Do this first
Prioritize by confirmed exploitation, then by ransomware linkage and exploitation probability.
- Patch GitLab for CVE-2026-85706 now. It is KEV-listed and exploited a day after disclosure.
- Patch ConnectWise ScreenConnect (CVE-2026-84869) and JFrog Artifactory (CVE-2026-42016, CVE-2026-42018).
- Patch Check Point VPN gateways for CVE-2026-85102 and CVE-2026-85103 ahead of imminent exploitation.
- Review ransomware-linked KEV items on your perimeter: SonicWall SMA1000, cPanel and WHM, PAN-OS, and VMware vCenter.
- Harden Microsoft 365 against passkey-themed phishing and invoice fraud, and confirm your Windows KEV-linked cumulative updates are applied.
Check your own state
To confirm where your environment stands against these adds, the free Microsoft Patch Tracker from Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily so GitLab, ScreenConnect, and Artifactory show up as they land. Siemserva also offers three free unlimited audits of your Microsoft 365, Intune, Defender, and Entra ID environment if you want to check identity and configuration exposure alongside patch state.
Sources
- BleepingComputer: GitLab urges users to patch max severity path traversal flaw (2026-09-11)
- SecurityWeek: GitLab Vulnerability Exploited One Day After Disclosure (2026-09-11)
- CISA Cybersecurity Advisories: CISA Adds One Known Exploited Vulnerability to Catalog (2026-09-11)
- CISA Cybersecurity Advisories: CISA Adds Three Known Exploited Vulnerabilities to Catalog (2026-09-11)
- BleepingComputer: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent (2026-09-12)
- SecurityWeek: Check Point Patches Critical VPN Vulnerabilities (2026-09-11)
- Rapid7: Metasploit Wrap Up: This One Goes to Sixteen! (2026-09-11)
- BleepingComputer: Passkey-themed phishing attacks lead to Microsoft 365 data theft (2026-09-11)
- The Record: Microsoft sees some new wrinkles in invoice-scam emails (2026-09-11)
- Help Net Security: Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited (2026-09-13)
- SecurityWeek: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days (2026-09-12)
- Help Net Security: AI agents exploited PaperCut flaws to breach 395 organizations (2026-09-11)
- BleepingComputer: Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs (2026-09-11)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-13.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.