ConnectWise ScreenConnect exploited in worm-like attacks
The item to act on first today is ConnectWise ScreenConnect. SecurityWeek reports that ConnectWise has patched a vulnerability that is already being exploited in worm-like attacks. Worm behavior means one compromised instance can spread to others without an operator driving each step, so a slow patch cycle here is a real problem. ScreenConnect is a remote access tool, which makes it a high-value foothold for anyone who reaches it.
If you run ScreenConnect on-premises, apply the fixed version now and treat any exposed instance as a priority over routine patching. Confirm you are on the patched build rather than assuming your update channel already handled it.
JFrog Artifactory and GitLab under active exploitation
Two more software supply-chain targets are in play. SecurityWeek reports three JFrog Artifactory flaws exploited to deploy backdoors. Artifactory sits in the middle of build and release pipelines, so a backdoor there can poison artifacts that flow to everything downstream.
GitLab remains hot as well. Rapid7 published analysis of CVE-2026-85706, a critical GitLab path traversal exploited in the wild, alongside CVE-2026-87719, and BleepingComputer earlier urged users to patch the maximum severity path traversal flaw. If you host GitLab, patch it and check for signs of file access abuse.
Exploited CVEs still topping the KEV list
No new CISA KEV additions came through since 2026-09-12, but the catalog's existing entries are the ones attackers are working through. Several carry ransomware links, which is the line between patch eventually and patch now.
CVE-2026-15409 in SonicWall SMA1000 appliances (CVSS 10, ransomware-linked, KEV), CVE-2026-41940 in WebPros cPanel and WHM (CVSS 9.8, ransomware-linked, KEV, EPSS 0.9853), CVE-2026-59310 in Broadcom VMware vCenter (CVSS 9.8, ransomware-linked, KEV), and CVE-2026-0257 in Palo Alto Networks PAN-OS (CVSS 9.1, ransomware-linked, KEV, EPSS 0.9516) all sit at the top of the exploited list. CVE-2026-20079, the Cisco Firewall Management Center authentication bypass with a CVSS of 10, is also KEV-listed and now has Metasploit coverage per Rapid7. Prioritize any of these that touch your perimeter.
September Windows updates are breaking things
Microsoft's September rollout is causing side effects worth planning around. BleepingComputer reports the September updates break audio on some Windows PCs, tied to KB5124012, and separately that the updates cause Remote Desktop Services failures on Windows Server. Microsoft also fixed Teams and Outlook launch failures on ARM Windows PCs from an earlier issue.
None of this is a reason to skip patching, given the exploited flaws above. It is a reason to stage deployment, test audio and RDS on a pilot ring, and have rollback notes ready before pushing to your server fleet.
Do this first
A short, grounded list for today:
- Patch ScreenConnect immediately and treat internet-exposed instances as compromised until verified.
- Patch GitLab for CVE-2026-85706 and update JFrog Artifactory, then hunt for backdoors and unexpected file access.
- Prioritize the ransomware-linked KEV entries on your perimeter: SonicWall CVE-2026-15409, cPanel CVE-2026-41940, VMware vCenter CVE-2026-59310, and PAN-OS CVE-2026-0257.
- Stage September Windows updates against the KB5124012 audio issue and the reported RDS failures before broad rollout.
Confirm your own patch state
To see where you actually stand against these exploited flaws, the free Microsoft Patch Tracker from Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and a companion tracker follows non-Microsoft KEV additions daily. If you want to check your own Microsoft 365, Intune, Defender, and Entra ID tenant, Siemserva also offers three free unlimited audits after a one-time registration.
Sources
- SecurityWeek: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks (2026-09-14)
- SecurityWeek: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment (2026-09-14)
- BleepingComputer: Microsoft: September updates break audio on some Windows PCs (2026-09-14)
- BleepingComputer: Microsoft: September updates cause RDS failures on Windows Server (2026-09-14)
- Rapid7: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild (2026-09-14)
- BleepingComputer: GitLab urges users to patch max severity path traversal flaw (2026-09-11)
- Rapid7: Metasploit Wrap Up: This One Goes to Sixteen! (2026-09-11)
- CISA Cybersecurity Advisories: CISA Adds Three Known Exploited Vulnerabilities to Catalog (2026-09-11)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-14.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.