This day 02:06 06:06 10:07 14:07 18:08 22:08
⚠ exploit status: CVE-2026-87491 · KEV CVE-2026-42016 · KEV CVE-2026-42018 · KEV CVE-2026-84869 · KEV CVE-2026-85706 · KEV
High  2026-09-12 02:06Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-09-12 — Four KEV additions hit DevOps and remote-access tools

CISA has added four newly confirmed exploited-in-the-wild vulnerabilities to its KEV catalog in a single batch, spanning GitLab, JFrog Artifactory (two separate flaws), and ConnectWise ScreenConnect. All four enable unauthenticated or low-privilege attackers to escalate to file reads, token theft, or full privilege escalation on enterprise infrastructure. The Chromium V8 out-of-bounds write (CVE-2026-87491KEV) also remains in KEV but saw no new development beyond Microsoft Edge ingesting the upstream patch.

Top items

Themes

KEV batch targets unauthenticated entry points. All four additions exploit missing or broken authentication/authorization at the perimeter — no credentials needed for initial access. Three of the four (GitLab, both JFrog CVEs) affect DevOps infrastructure that often holds source code, build artifacts, and deployment secrets, making post-exploitation impact disproportionately high relative to exploit complexity.

JFrog Artifactory under sustained pressure. With two new KEV entries alongside the previously reported backdoor-deployment campaign, Artifactory is accumulating multiple confirmed-exploited vulnerabilities in a two-week window, suggesting active and systematic targeting of self-hosted instances.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db