⚠️ LiveThreat Vulnerability Brief — Sep 12, 2026
🧭 Critical vulnerability exploits surge in core SaaS and network tools
📌 What happened: Today two high‑impact flaws were highlighted—a Check Point VPN bug and several actively‑exploited bugs in Artifactory, ScreenConnect and RouterOS—continuing the week‑long pattern of vulnerability‑driven attacks.
⚖️ Why it matters for compliance: Unpatched flaws let attackers bypass controls, so keeping access tightly managed and vendors closely watched is essential for audit readiness.
🎯 Who's affected: The alerts hit technology and SaaS providers, especially those offering VPN, artifact repositories, remote support and routing equipment.
✅ Recommended actions:
• Apply the latest patches for Check Point VPN and all listed vendor products
• Validate that MFA and least‑privilege rules protect remote admin interfaces
• Add these advisories to your vendor‑risk monitoring workflow
━━━━━━━━━━━━━━━━━━━━━━
📰 The headlines behind this brief:
💥 Critical Check Point VPN Flaws (CVE‑2026‑85102 & CVE‑2026‑85103) Enable Remote Code Execution – Exploitation Imminent
The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN gateways (CVE‑2026‑85102, CVE‑2026‑85103) are likely to be exploited soon, allowing re…
🔗 https://www.verisq.ai/intelligence/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent-59829
⚠️ Critical CVE-2026-85706 Path Traversal in GitLab Enables Unauthenticated File Read
GitLab disclosed CVE‑2026‑85706, a CVSS 10.0 path‑traversal flaw in the Repository Commits API that lets unauthenticated actors read arbitrary server files. The…
🔗 https://www.verisq.ai/intelligence/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure-59608
🦠 Critical Authentication‑Bypass Chain in JFrog Artifactory Enables Admin Token Theft and Rust Backdoor Deployment
Threat actors are chaining three newly disclosed Artifactory CVEs to steal JWTs, elevate privileges, and drop a Rust backdoor. The exploit highlights the need …
🔗 https://www.verisq.ai/intelligence/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware-59602
⚠️ Critical Path Traversal (CVE‑2026‑85706) in GitLab Repository Commits API Allows Unauthenticated File Read
GitLab disclosed CVE‑2026‑85706, a max‑severity path‑traversal flaw that lets unauthenticated attackers read arbitrary files via the Repository Commits API. The…
🔗 https://www.verisq.ai/intelligence/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw-59604
💀 Critical Authentication Bypass in Cisco FMC (CVE‑2026‑20079) Enables Credential Theft and Ransomware Deployment
Cisco’s Secure Firewall Management Center contains a critical authentication‑bypass flaw (CVE‑2026‑20079, CVSS 10.0) that attackers are using to steal admin cre…
🔗 https://www.verisq.ai/intelligence/cisco-fmc-flaws-exploited-to-steal-credentials-and-deploy-qilin-ransomware-59616
⚠️ Unauthenticated PHP Object Injection (CVE‑2026‑80428) Enables Remote Code Execution in ILIAS LMS
🔗 https://www.verisq.ai/intelligence/remote-cve-2026-80428-unauthenticated-php-object-injection-via-shibboleth-ilias-9-22-10-0-10-10-11-0-11-3-rce-59703
💥 Critical Authorization Bypass in JFrog Artifactory (CVE‑2026‑42016) and Related Actively‑Exploited Flaws Added to CISA K…
🔗 https://www.verisq.ai/intelligence/cisa-adds-5-actively-exploited-artifactory-screenconnect-and-routeros-flaws-to-kev-59830
━━━━━━━━━━━━━━━━━━━━━━
🛡️ Which of your controls does each of these touch? Continuous evidence is what makes an audit defensible.
📖 View all → https://www.verisq.ai/vulnerabilities
🔔 Follow LiveThreat for daily threat intelligence + compliance readiness
#TrustOperations #NISTCSF #ControlAssurance #Cybersecurity #ThreatIntel #ContinuousMonitoring #BreachWatch #VerisqAI #LiveThreat