Threat Intelligence Briefing September 2026 — GitLab CVSS 10.0 and ScreenConnect KEV

GitLab Hits CVSS 10.0, ScreenConnect Joins KEV Same Week

September 14, 2026•3 min read

Two Known Exploited Vulnerabilities landed the same week, and they point at two different failure modes. One is a perfect-10 flaw in the platform that holds your source code. The other is a privilege-escalation bug in the tool your managed service provider uses to reach into your network. Here's what matters.

GitLab's CVSS 10.0 path-traversal flaw

CISA added CVE-2026-85706 to the Known Exploited Vulnerabilities catalog on September 11 with a remediation deadline of September 14 — and flagged it for forensic triage under BOD 26-04, meaning the working assumption is that vulnerable systems may already have been accessed, not just that they're now patchable. The flaw sits in GitLab's repository commits API: an unauthenticated attacker can read arbitrary files from a self-hosted GitLab Community or Enterprise Edition instance — source code, CI/CD pipeline configuration, stored deployment credentials, cloud tokens. If your GitLab is internet-facing, treat this as a supply-chain incident candidate until proven otherwise.

Sector impact: any regulated environment running self-hosted GitLab carries the same exposure — maritime engineering software groups, aviation MRO development shops, healthcare device-firmware teams. This isn't a defense-only problem; it's a self-hosted-DevOps problem.

ConnectWise ScreenConnect joins the KEV list

CVE-2026-84869 — improper privilege management and missing authorization that lets an attacker transfer files and execute code through an active remote session without authorization or host confirmation. CISA added it the same day as GitLab, September 11. ScreenConnect is remote-monitoring-and-management tooling — the software a managed service provider uses to reach into every client's environment at once. A compromise here isn't one organization's exposure. It's every downstream client the MSP touches, through a single trusted channel.

Sector impact: this is an MSP-relationship risk, not a sector-specific one — any client who outsources IT support through a provider running ScreenConnect inherits this exposure the moment the tool is compromised, regardless of what industry that client is in.

Watch: the edge-device pattern adds three more vendors

In the same ten-day window, CISA also added authentication-bypass flaws in Citrix NetScaler and Cisco Firewall Management Center, plus two MikroTik RouterOS bugs that CERT Polska confirmed are being chained together in the wild to take over internet-exposed devices. This is the same class flagged in prior briefings — perimeter infrastructure that sits outside routine patch cycles because nobody thinks of the edge as an endpoint.

Sector impact: MikroTik RouterOS shows up constantly in OT and industrial network gear — this cluster reaches beyond the DIB perimeter into operational technology environments running the same device class.

Quick hits by sector

DIB: GitLab, ScreenConnect, and the edge-device cluster all land inside typical SSP boundaries this week. Maritime: the Coast Guard stood up a new Office of Maritime Cybersecurity Policy to centralize MTS cyber policy — a governance move worth knowing about, not an incident. Aviation: quiet this window. OT/ICS: eight new CISA ICS advisories plus research showing AI can now help port a working PLC exploit between device models in under nine hours. Healthcare: a multi-state home-health and hospice franchise network was added to two ransomware leak sites this week, including a group first tracked less than a year ago.

What this means

If you self-host GitLab, patch or mitigate today — CISA's deadline is today, and the right first move is checking whether you were already accessed, not just confirming the patch applied. If a managed service provider touches your environment, ask them directly this week whether ScreenConnect is patched. And if Citrix NetScaler, Cisco Firewall Management Center, or MikroTik RouterOS sit inside your boundary, this is the week to confirm patch status — not the week to file it as read.

What's your policy for verifying an MSP's own patch cadence — do you ask, or do you trust the MSA?

Security brings compliance. Compliance does not bring security.

Craig Wood | CISM | CCA Lead Assessor | ISO/IEC 27001 Senior Lead Auditor | CEO, PSY Logistics Technology Partners
CMMC | Maritime Cybersecurity | vCISO | DIB

Back to Blog