CISA Adds Three Actively Exploited Software Flaws

The GitLab flaw affects both Community Edition and Enterprise Edition across three vulnerable branches: versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Administrators can remediate by upgrading within their current branch rather than moving to the latest major release.
watchTowr reported that exploitation of CVE-2026-85706 may require only a single HTTP request and observed probing shortly after the patch was released, warning that widespread exploitation could follow quickly.
Organizations investigating possible GitLab exploitation should search logs for HTTP POST requests to `/api/v4/projects/{id}/repository/commits/` that include `file.path` parameters, a pattern associated with attempts to abuse the vulnerable API.
The GitLab server process’s file permissions determine the potential exposure: attackers could access not only application configuration and source-related data, but also database passwords, API tokens, SSH keys, and log files containing internal hostnames and user activity.
The Artifactory attacks were observed between August 15 and September 8 and combined the two KEV-listed flaws with CVE-2026-82329. The intrusions reportedly included creating persistent administrator accounts, deploying malicious plugins, and installing backdoors on self-hosted servers.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited software vulnerabilities to its Known Exploited Vulnerabilities catalog, urging organizations to patch immediately. The most critical is GitLab's CVE-2026-85706, a maximum-severity flaw that allows unauthenticated attackers to read sensitive files like credentials and SSH keys from self-hosted servers CISA.
The GitLab flaw joins flaws in JFrog Artifactory and ConnectWise ScreenConnect that attackers are actively exploiting in real-world attacks. Researchers observed probing activity shortly after patches were released, signaling that widespread exploitation could accelerate quickly Dark Reading.
CVE-2026-85706 has a CVSS score of 10.0, the highest possible severity rating. It is a path-traversal vulnerability in GitLab's repository commits API that requires no authentication to exploit. Attackers can read arbitrary files from the server with a single HTTP POST request to `/api/v4/projects/{id}/repository/commits/` WebProNews.
The flaw affects Community Edition and Enterprise Edition versions 18.7 through 19.3. GitLab released patches on September 10 in versions 19.3.2, 19.2.6, and 19.1.8. Self-hosted administrators should upgrade or restrict internet access immediately. GitLab.com and Dedicated customers are already protected Yahoo Tech.
Attackers can steal database passwords, API tokens, SSH keys, configuration data, and CI/CD secrets depending on file permissions. Organizations should search logs for suspicious POST requests containing `file.path` parameters to detect exploitation attempts Real Hacker.
Attackers have exploited two Artifactory vulnerabilities together to bypass authorization controls and gain administrative access. The campaign ran from August 15 to September 8, combining the two Known Exploited Vulnerabilities with a third flaw, CVE-2026-82329 Dark Reading.
Once inside, attackers created persistent administrator accounts, deployed malicious plugins, and installed backdoors on self-hosted Artifactory servers. These tactics allow them to maintain long-term access and execute arbitrary code without detection Archynetys.
A ScreenConnect client vulnerability allows attackers to transfer files and execute code during active remote support sessions. Security researchers have linked the flaw to malicious VBScript deliveries targeting remote desktop users CISA.
ConnectWise recommends updating to version 26.6.5 or later to close the vulnerability. Organizations relying on ScreenConnect for remote support should prioritize this patch to prevent unauthorized access WebProNews.
Organizations running self-managed GitLab, Artifactory, and ScreenConnect installations carry significantly higher risk because they do not automatically receive patches. Customers using cloud-based or managed versions are typically protected by vendors before public disclosure Dark Reading.
CISA has made these three flaws mandatory reporting items for federal agencies and contractors. Any organization handling sensitive data should treat these patches as emergency priorities to prevent supply chain compromise Yahoo Tech.
Publishers
14
Articles
4
Reach
18