All posts

ScreenConnect worm-like attacks and September Windows patch fallout

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 14, 2026

ConnectWise ScreenConnect exploited in worm-like attacks

The item to act on first today is ConnectWise ScreenConnect. SecurityWeek reports that ConnectWise has patched a vulnerability that is already being exploited in worm-like attacks. Worm behavior means one compromised instance can spread to others without an operator driving each step, so a slow patch cycle here is a real problem. ScreenConnect is a remote access tool, which makes it a high-value foothold for anyone who reaches it.

If you run ScreenConnect on-premises, apply the fixed version now and treat any exposed instance as a priority over routine patching. Confirm you are on the patched build rather than assuming your update channel already handled it.

JFrog Artifactory and GitLab under active exploitation

Two more software supply-chain targets are in play. SecurityWeek reports three JFrog Artifactory flaws exploited to deploy backdoors. Artifactory sits in the middle of build and release pipelines, so a backdoor there can poison artifacts that flow to everything downstream.

GitLab remains hot as well. Rapid7 published analysis of CVE-2026-85706, a critical GitLab path traversal exploited in the wild, alongside CVE-2026-87719, and BleepingComputer earlier urged users to patch the maximum severity path traversal flaw. If you host GitLab, patch it and check for signs of file access abuse.

Exploited CVEs still topping the KEV list

No new CISA KEV additions came through since 2026-09-12, but the catalog's existing entries are the ones attackers are working through. Several carry ransomware links, which is the line between patch eventually and patch now.

CVE-2026-15409 in SonicWall SMA1000 appliances (CVSS 10, ransomware-linked, KEV), CVE-2026-41940 in WebPros cPanel and WHM (CVSS 9.8, ransomware-linked, KEV, EPSS 0.9853), CVE-2026-59310 in Broadcom VMware vCenter (CVSS 9.8, ransomware-linked, KEV), and CVE-2026-0257 in Palo Alto Networks PAN-OS (CVSS 9.1, ransomware-linked, KEV, EPSS 0.9516) all sit at the top of the exploited list. CVE-2026-20079, the Cisco Firewall Management Center authentication bypass with a CVSS of 10, is also KEV-listed and now has Metasploit coverage per Rapid7. Prioritize any of these that touch your perimeter.

September Windows updates are breaking things

Microsoft's September rollout is causing side effects worth planning around. BleepingComputer reports the September updates break audio on some Windows PCs, tied to KB5124012, and separately that the updates cause Remote Desktop Services failures on Windows Server. Microsoft also fixed Teams and Outlook launch failures on ARM Windows PCs from an earlier issue.

None of this is a reason to skip patching, given the exploited flaws above. It is a reason to stage deployment, test audio and RDS on a pilot ring, and have rollback notes ready before pushing to your server fleet.

Do this first

A short, grounded list for today:

  • Patch ScreenConnect immediately and treat internet-exposed instances as compromised until verified.
  • Patch GitLab for CVE-2026-85706 and update JFrog Artifactory, then hunt for backdoors and unexpected file access.
  • Prioritize the ransomware-linked KEV entries on your perimeter: SonicWall CVE-2026-15409, cPanel CVE-2026-41940, VMware vCenter CVE-2026-59310, and PAN-OS CVE-2026-0257.
  • Stage September Windows updates against the KB5124012 audio issue and the reported RDS failures before broad rollout.

Confirm your own patch state

To see where you actually stand against these exploited flaws, the free Microsoft Patch Tracker from Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and a companion tracker follows non-Microsoft KEV additions daily. If you want to check your own Microsoft 365, Intune, Defender, and Entra ID tenant, Siemserva also offers three free unlimited audits after a one-time registration.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-14.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.