The 5-Minute Cyber Brief: September 14, 2026

By George Bailey   Published: 09/13/26   Updated: 09/13/26   2 min read

Published: 09/14/26

Monday’s pattern is short clocks and shared blast radius: a GitLab file-read that went from disclosure to KEV in a day (federal due today), a ScreenConnect client bug that turns support sessions into host compromise (also due today), Chrome’s seventh exploited zero-day of 2026, and a WatchGuard Firebox RCE that CISA has now flagged for ransomware use.

Lead Story

GitLab CVE-2026-85706: Unauth File Read — Patch by Today

CVE-2026-85706 is a CVSS 10.0 path traversal in GitLab’s repository commits API. An unauthenticated attacker can read arbitrary server files. Fixed in 19.3.2 / 19.2.6 / 19.1.8. watchTowr saw probes within ~24 hours; CISA KEV due September 14, 2026.

Why it matters: Patch self-managed CE/EE now, hunt file.path POSTs to the commits API, and rotate secrets if the instance was exposed.

Read more on CyberExperts: Read the analysis

Also Worth Your Attention

ScreenConnect Client: Session Transfer Without Host OK

CVE-2026-84869 (CVSS 9.9) lets a low-privilege active session transfer and execute files on the host without confirmation. Fix: client 26.6.5+, then reinstall host clients/agents. Huntress linked observed VBScript worm-like spread. KEV due September 14.

Why it matters: Upgrade on-prem, refresh every agent, or strip TransferFiles permissions until you can.

Read more on CyberExperts: Read more

Chrome’s Seventh Exploited Zero-Day of 2026

CVE-2026-87491 is a V8 out-of-bounds write fixed in Chrome 153.0.8010.36/.37. Google confirms an in-the-wild exploit. CISA added it to KEV on September 9.

Why it matters: Force Chromium-family browsers to 153+ and relaunch — sandbox RCEs rarely travel alone.

Read more on CyberExperts: Read more

WatchGuard Firebox: Ransomware Now Named on an Old Edge RCE

CVE-2025-14733 (iked OOB write, unauth RCE) was already in KEV. On September 10, CISA updated the entry to mark known ransomware campaign use. ~9,000 Fireboxes still exposed online per Shadowserver-linked reporting.

Why it matters: Get to fixed Fireware builds, hunt WatchGuard IoCs, and rotate Firebox-stored secrets if you were exposed.

Read more on CyberExperts: Read the analysis

Go Deeper

Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.