Why Should I Care? โ€” 2026-09-12 | ๐Ÿ”ด 2 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 16 RADAR ยท โšช 72 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-12

18 vendor intel items scanned  |  ๐Ÿ”ด 2 HIGH  |  ๐ŸŸก 0 MEDIUM  |  ๐Ÿ”ต 16 RADAR  |  โšช 72 FILTERED

๐Ÿ”ด Critical โ€” action required:

  1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-85706) โ€” Yes, if you run GitLab Community Edition or Enterprise Edition versions 14.2.0 to 14.10.5: this path traversal vulnerability allows attackers to access sensitive files and directories.
  2. CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-42016, CVE-2026-42018, CVE-2026-84869) โ€” Yes, if you run JFrog Artifactory or ConnectWise ScreenConnect versions affected by the listed CVEs: these vulnerabilities are actively exploited and pose significant risks.

Everything else can wait.

๐Ÿ”ต 15 items on the radar โ€” see below โ†“


Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now


CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories [CISA KEV] | CVSS 8.8 | CVE-2026-85706

โ“ Why Should I Care?
Yes, if you run GitLab Community Edition or Enterprise Edition versions 14.2.0 to 14.10.5: this path traversal vulnerability allows attackers to access sensitive files and directories.

๐ŸŽฏ Affected versions: 14.2.0 to 14.10.5
Not affected: 14.10.6 and later

๐ŸŽญ In plain English:
This vulnerability means an attacker can trick the system into revealing files and directories it shouldn't, like sensitive configuration files or user data. For example, an attacker could access and steal sensitive configuration files that contain database passwords.

๐Ÿ”ง Prerequisites:

  • Running GitLab versions 14.2.0 to 14.10.5
  • Publicly exposed GitLab instance

โฑ Urgency: High urgency due to active exploitation and the risk of total control over the asset post-exploitation.

โœ… Fixed in: 14.10.6, 14.11.0

๐Ÿ’ก Context: The root cause is improper validation of user input that is used to construct file paths.


CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA Advisories [CISA KEV] | CVE-2026-42016, CVE-2026-42018, CVE-2026-84869

โ“ Why Should I Care?
Yes, if you run JFrog Artifactory or ConnectWise ScreenConnect versions affected by the listed CVEs: these vulnerabilities are actively exploited and pose significant risks.

๐ŸŽฏ Affected versions: JFrog Artifactory versions prior to 7.28.5, ConnectWise ScreenConnect versions prior to 12.3.4
Not affected: JFrog Artifactory 7.28.5 and later, ConnectWise ScreenConnect 12.3.4 and later

๐ŸŽญ In plain English:
These vulnerabilities allow attackers to gain unauthorized access to your systems and escalate privileges, potentially taking full control. For example, an attacker could log in as an admin and steal sensitive data or deploy malware.

๐Ÿ”ง Prerequisites:

  • Running an affected version of JFrog Artifactory or ConnectWise ScreenConnect
  • Publicly exposed services

โฑ Urgency: High urgency due to active exploitation and the risk of full system compromise.

โœ… Fixed in: 7.28.5, 12.3.4

๐Ÿ’ก Context: The vulnerabilities stem from flaws in the authentication and authorization mechanisms, allowing unauthorized access and privilege escalation.


Why Should I Care? ๐ŸŸก MEDIUM (0)

None.


Why Should I Care? ๐Ÿ”ต On the Radar (16)


โšช 72 low-priority items filtered.


๐Ÿฆ… Aggregated and triaged by Donna AI  |  Sources: 8 vendor feeds  |  CISA KEV

Read more

Why Should I Care? โ€” 2026-09-24 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-24 27 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 15 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-23 | ๐Ÿ”ด 5 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-23 35 vendor intel items scanned ย |ย  ๐Ÿ”ด 5 HIGH ย |ย  ๐ŸŸก 3 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-22 | ๐Ÿ”ด 1 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 17 RADAR ยท โšช 66 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-22 18 vendor intel items scanned ย |ย  ๐Ÿ”ด 1 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 17 RADAR ย |ย  โšช 66 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-21 | ๐Ÿ”ด 23 HIGH ยท ๐ŸŸก 32 MEDIUM ยท ๐Ÿ”ต 209 RADAR ยท โšช 73 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-21 264 vendor intel items scanned ย |ย  ๐Ÿ”ด 23 HIGH ย |ย  ๐ŸŸก 32 MEDIUM ย |ย  ๐Ÿ”ต 209 RADAR ย |ย  โšช 73 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) โ€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic