HomeIntelligenceBrief
BREACH BRIEF

Vulnerability Brief — September 12, 2026

7 items in DIGEST_VULN digest.

LiveThreat™ Intelligence · 📅 September 12, 2026

⚠️ LiveThreat Vulnerability Brief — Sep 12, 2026

🧭 Critical vulnerability exploits surge in core SaaS and network tools

📌 What happened: Today two high‑impact flaws were highlighted—a Check Point VPN bug and several actively‑exploited bugs in Artifactory, ScreenConnect and RouterOS—continuing the week‑long pattern of vulnerability‑driven attacks.

⚖️ Why it matters for compliance: Unpatched flaws let attackers bypass controls, so keeping access tightly managed and vendors closely watched is essential for audit readiness.

🎯 Who's affected: The alerts hit technology and SaaS providers, especially those offering VPN, artifact repositories, remote support and routing equipment.

✅ Recommended actions:

• Apply the latest patches for Check Point VPN and all listed vendor products

• Validate that MFA and least‑privilege rules protect remote admin interfaces

• Add these advisories to your vendor‑risk monitoring workflow

━━━━━━━━━━━━━━━━━━━━━━

📰 The headlines behind this brief:

💥 Critical Check Point VPN Flaws (CVE‑2026‑85102 & CVE‑2026‑85103) Enable Remote Code Execution – Exploitation Imminent

The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN gateways (CVE‑2026‑85102, CVE‑2026‑85103) are likely to be exploited soon, allowing re…

🔗 https://www.verisq.ai/intelligence/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent-59829

⚠️ Critical CVE-2026-85706 Path Traversal in GitLab Enables Unauthenticated File Read

GitLab disclosed CVE‑2026‑85706, a CVSS 10.0 path‑traversal flaw in the Repository Commits API that lets unauthenticated actors read arbitrary server files. The…

🔗 https://www.verisq.ai/intelligence/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure-59608

🦠 Critical Authentication‑Bypass Chain in JFrog Artifactory Enables Admin Token Theft and Rust Backdoor Deployment

Threat actors are chaining three newly disclosed Artifactory CVEs to steal JWTs, elevate privileges, and drop a Rust backdoor. The exploit highlights the need …

🔗 https://www.verisq.ai/intelligence/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware-59602

⚠️ Critical Path Traversal (CVE‑2026‑85706) in GitLab Repository Commits API Allows Unauthenticated File Read

GitLab disclosed CVE‑2026‑85706, a max‑severity path‑traversal flaw that lets unauthenticated attackers read arbitrary files via the Repository Commits API. The…

🔗 https://www.verisq.ai/intelligence/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw-59604

💀 Critical Authentication Bypass in Cisco FMC (CVE‑2026‑20079) Enables Credential Theft and Ransomware Deployment

Cisco’s Secure Firewall Management Center contains a critical authentication‑bypass flaw (CVE‑2026‑20079, CVSS 10.0) that attackers are using to steal admin cre…

🔗 https://www.verisq.ai/intelligence/cisco-fmc-flaws-exploited-to-steal-credentials-and-deploy-qilin-ransomware-59616

⚠️ Unauthenticated PHP Object Injection (CVE‑2026‑80428) Enables Remote Code Execution in ILIAS LMS

🔗 https://www.verisq.ai/intelligence/remote-cve-2026-80428-unauthenticated-php-object-injection-via-shibboleth-ilias-9-22-10-0-10-10-11-0-11-3-rce-59703

💥 Critical Authorization Bypass in JFrog Artifactory (CVE‑2026‑42016) and Related Actively‑Exploited Flaws Added to CISA K…

🔗 https://www.verisq.ai/intelligence/cisa-adds-5-actively-exploited-artifactory-screenconnect-and-routeros-flaws-to-kev-59830

━━━━━━━━━━━━━━━━━━━━━━

🛡️ Which of your controls does each of these touch? Continuous evidence is what makes an audit defensible.

📖 View all → https://www.verisq.ai/vulnerabilities

🔔 Follow LiveThreat for daily threat intelligence + compliance readiness

#TrustOperations #NISTCSF #ControlAssurance #Cybersecurity #ThreatIntel #ContinuousMonitoring #BreachWatch #VerisqAI #LiveThreat

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →