Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLa...
Attackers are exploiting three vulnerabilities in self-hosted JFrog Artifactory to gain administrator access in under five minutes. The vulnerabilities, CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329, allow for authentication bypass and privilege escalation. Attackers can chain these flaws to cr...
On September 11, 2026, CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These vulnerabilities include CVE-2026-42016, which has a CVSS score of 8.1. This update foll...
A critical vulnerability in ConfigServer Security & Firewall (CSF), tracked as CVE-2026-65638, was disclosed on September 10, 2026. This flaw affects CSF versions 14.00 through 16.29, allowing unauthenticated remote attackers to execute arbitrary commands via the MESSENGER service. Administrators ar...