All Articles

Critical Exploits Hit GitLab, ScreenConnect, and JFrog This Week

September 14, 2026 4 min read By The Vici Tech Solutions Team
VulnerabilitiesThreat IntelligenceCyber SecurityZero-Day

Multiple Critical Vulnerabilities Under Active Exploitation

This week brought a cascade of critical security advisories as CISA added several high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog. Three platforms in particular—GitLab, ConnectWise ScreenConnect, and JFrog Artifactory—are experiencing active exploitation that demands immediate attention from IT teams.

The common thread? These aren't theoretical vulnerabilities. Attackers are actively exploiting them in the wild, and organizations running these platforms need to patch immediately or face potential compromise.

GitLab Path Traversal: Maximum Severity Rating

CISA's warning about a maximum-severity GitLab vulnerability (CVE-2026-85706) affecting both Community Edition and Enterprise Edition represents one of the most serious threats this week. The path traversal flaw allows attackers to bypass security controls and access files outside their intended directory.

Path traversal vulnerabilities are particularly dangerous in development platforms like GitLab because they can expose:

  • Source code repositories containing proprietary business logic
  • Configuration files with database credentials and API keys
  • CI/CD pipeline secrets used for deployment
  • User authentication data

GitLab is widely deployed across software development teams, making this a high-value target for both cybercriminals and nation-state actors seeking intellectual property or supply chain access points.

Immediate action required: Update to the latest patched version of GitLab immediately. If patching cannot be completed within 24 hours, consider temporarily restricting network access to your GitLab instance to trusted IP addresses only.

ConnectWise ScreenConnect: Worm-Like Attack Pattern

ConnectWise has patched a ScreenConnect vulnerability that SecurityWeek reports is being exploited in worm-like attacks (CVE-2026-84869). The flaw allows attackers to send files and execute them without authorization through an active remote session.

This is particularly concerning because ScreenConnect is a remote monitoring and management (RMM) platform used by managed service providers and IT departments to access client systems. A compromise here creates a multiplier effect—one vulnerable ScreenConnect server can provide access to dozens or hundreds of managed endpoints.

The "worm-like" attack pattern suggests automated exploitation, meaning attackers are likely scanning for vulnerable instances and compromising them at scale rather than targeting specific organizations.

Defense strategy:

  • Apply the ScreenConnect patch immediately
  • Review access logs for unauthorized file transfers or command execution
  • Implement network segmentation to limit lateral movement if an RMM tool is compromised
  • Enable multi-factor authentication for all ScreenConnect access
  • Consider restricting ScreenConnect access to VPN-connected administrators only

JFrog Artifactory: Supply Chain Entry Point

Three JFrog Artifactory vulnerabilities (CVE-2026-42016, CVE-2026-42018, and a third unnamed flaw) are being exploited for backdoor deployment, according to SecurityWeek. These vulnerabilities allow attackers to bypass authentication and elevate privileges to administrator level.

Artifactory serves as a central repository for software artifacts—compiled code, libraries, dependencies, and container images. Compromising an Artifactory instance provides attackers with an ideal supply chain attack vector. They can:

  • Inject malicious code into legitimate software packages
  • Replace trusted dependencies with trojanized versions
  • Exfiltrate proprietary code and intellectual property
  • Establish persistent access through backdoored build artifacts

This attack pattern mirrors the tactics we've seen in recent supply chain incidents where attackers compromise development infrastructure to distribute malware through trusted software update mechanisms.

Mitigation steps:

  • Patch JFrog Artifactory to the latest version immediately
  • Audit all administrator accounts and recent privilege escalations
  • Review artifact upload logs for suspicious or unauthorized packages
  • Implement integrity checking for critical artifacts
  • Consider re-scanning previously uploaded artifacts for indicators of compromise

Additional Critical Vulnerabilities This Week

Beyond these three high-profile exploits, CISA's catalog additions include:

  • MikroTik RouterOS (CVE-2026-86060, CVE-2026-67277): Command injection and authentication bypass vulnerabilities in widely deployed routers
  • Citrix NetScaler (CVE-2026-19490): Authentication bypass affecting enterprise load balancers and VPN gateways
  • Cisco Firewall Management Center (CVE-2026-20079): Authentication bypass in centralized firewall management platforms
  • Microsoft Windows (CVE-2026-81963, CVE-2026-85880): Link following and heap-based buffer overflow vulnerabilities

Each of these represents infrastructure-level access that attackers can leverage for initial access or lateral movement.

The Patching Window Continues to Shrink

The time between vulnerability disclosure and active exploitation continues to compress. Several of the vulnerabilities added to CISA's KEV catalog this week were disclosed and exploited within days, not weeks or months.

This acceleration creates a challenging environment for IT teams:

  • Patches must be tested and deployed faster
  • Change management windows that once seemed reasonable are now dangerously slow
  • Automated patching for critical infrastructure becomes increasingly necessary
  • Compensating controls (network segmentation, access restrictions) must be in place before exploitation begins

Organizations that maintain a quarterly or even monthly patching cycle for internet-facing infrastructure are operating with unacceptable risk in 2026.

Building a Rapid Response Capability

To defend against this threat landscape, organizations need:

Asset inventory: You cannot patch what you don't know you have. Maintain an accurate, automatically updated inventory of all internet-facing systems and critical internal infrastructure.

Vulnerability scanning: Regular automated scanning with immediate alerting for critical and high-severity findings.

Patch testing environment: A staging environment that mirrors production allows rapid patch validation without risking operational disruption.

Emergency change procedures: Pre-approved processes for deploying critical security patches outside normal change windows.

Compensating controls: Network segmentation, web application firewalls, and access restrictions that can be deployed within hours when patching will take days.

Verify Your Security Posture

The vulnerabilities exploited this week highlight a fundamental question: would your organization detect an attacker who gained initial access through one of these flaws? Regular penetration testing provides visibility into both patchable vulnerabilities and the detection capabilities that determine whether exploitation leads to full compromise.

If you need help assessing your exposure to these or other critical vulnerabilities, contact Vici Tech Solutions to discuss penetration testing and security assessment services tailored to your infrastructure.

Worried about the threats you just read about?

Vici Tech Solutions helps businesses across the US find and fix vulnerabilities before attackers do. Explore our penetration testing services or talk to us about your security posture.

Get a Security Assessment