Published: 09/14/26
Monday’s pattern is short clocks and shared blast radius: a GitLab file-read that went from disclosure to KEV in a day (federal due today), a ScreenConnect client bug that turns support sessions into host compromise (also due today), Chrome’s seventh exploited zero-day of 2026, and a WatchGuard Firebox RCE that CISA has now flagged for ransomware use.
Lead Story
GitLab CVE-2026-85706: Unauth File Read — Patch by Today
CVE-2026-85706 is a CVSS 10.0 path traversal in GitLab’s repository commits API. An unauthenticated attacker can read arbitrary server files. Fixed in 19.3.2 / 19.2.6 / 19.1.8. watchTowr saw probes within ~24 hours; CISA KEV due September 14, 2026.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Patch self-managed CE/EE now, hunt file.path POSTs to the commits API, and rotate secrets if the instance was exposed.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
ScreenConnect Client: Session Transfer Without Host OK
CVE-2026-84869 (CVSS 9.9) lets a low-privilege active session transfer and execute files on the host without confirmation. Fix: client 26.6.5+, then reinstall host clients/agents. Huntress linked observed VBScript worm-like spread. KEV due September 14.
Why it matters: Upgrade on-prem, refresh every agent, or strip TransferFiles permissions until you can.
Read more on CyberExperts: Read more
Chrome’s Seventh Exploited Zero-Day of 2026
CVE-2026-87491 is a V8 out-of-bounds write fixed in Chrome 153.0.8010.36/.37. Google confirms an in-the-wild exploit. CISA added it to KEV on September 9.
Why it matters: Force Chromium-family browsers to 153+ and relaunch — sandbox RCEs rarely travel alone.
Read more on CyberExperts: Read more
WatchGuard Firebox: Ransomware Now Named on an Old Edge RCE
CVE-2025-14733 (iked OOB write, unauth RCE) was already in KEV. On September 10, CISA updated the entry to mark known ransomware campaign use. ~9,000 Fireboxes still exposed online per Shadowserver-linked reporting.
Why it matters: Get to fixed Fireware builds, hunt WatchGuard IoCs, and rotate Firebox-stored secrets if you were exposed.
Read more on CyberExperts: Read the analysis
Go Deeper
Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.