Monday, September 14, 2026 | Jonathan Brown

Command View


Verification cutoff

September 14, 2026, 14:15 UTC. Only information available and independently verifiable by that cutoff is included.

Priority posture: RED

Active exploitation is confirmed against three high-value administrative layers: software-artifact infrastructure, GitLab servers and ScreenConnect remote-support clients. Separately, a weaponized Sogou Input Method chain has been used to deliver the GRAYRABBIT backdoor.

The common operational risk is not merely endpoint compromise. These products sit in software provenance, source-code, remote-administration and user-access paths. Successful exploitation can invalidate trust in credentials, artifacts, automation and administrative activity conducted during the exposed period.

Status definitions: RED—confirmed exploitation or active incident requiring containment, forensic triage and remediation; AMBER—serious exploitable exposure requiring urgent action; WATCH—validated development requiring monitoring or inventory; CONTEXT—strategic, regulatory or physical operating condition.

Today’s decisions

PriorityDecisionOwner/function
REDTreat internet-accessible, self-hosted JFrog Artifactory systems not on cumulative fixed releases as potentially compromised—not merely vulnerable.Platform engineering, DevSecOps, incident response
REDUpgrade vulnerable self-managed GitLab instances today and conduct forensic triage for unauthorized file access. The federal remediation date is September 14.GitLab owner, infrastructure security, incident response
REDComplete ScreenConnect 26.6.5 server and client/agent remediation. Disable file transfer until client coverage is verified.Remote-support owner, MSP governance, endpoint security
RED where installedVerify Sogou Input Method is at least 16.3.0.3498; remove it where unnecessary and hunt for the published GRAYRABBIT chain.Endpoint engineering, threat hunting
RED—overdueConfirm closure of exposed MikroTik RouterOS systems. The relevant CISA remediation date passed September 13.Network engineering, OT/remote-site operations

Threat and Resilience Ledger


1. RED — JFrog Artifactory flaws are being combined into administrative compromise paths

Wiz reports exploitation of CVE-2026-42016, CVE-2026-42018 and CVE-2026-82329 across multiple self-hosted Artifactory environments. Activity was observed from August 15 through September 8; in some cases, an attacker created a persistent administrative account within five minutes.

The most important newly documented path combines:

  • CVE-2026-42018: exposure of an internal anonymous-user token, including in configurations where anonymous access was disabled.
  • CVE-2026-42016: insufficient enforcement of a token’s intended scope, allowing a low-privilege token to be exchanged for administrative scope.

Wiz observed an unauthenticated request to the trailing-slash form of /access/api/v1/aws/token/, followed by a request to /access/api/v1/tokens and creation of an administrative user. Reported post-exploitation behavior varied by actor and included persistent accounts, malicious Groovy plugins, command execution, web shells and second-stage Rust backdoors.

CVE-2026-82329 provides a separate authentication-bypass path in default configurations. Wiz observed successful requests to /access/api/v1/registry/join, followed by administrative-token use, configuration access, long-lived token creation and collection of sensitive trust material.

JFrog Cloud environments received vendor-side protections. Self-hosted operators should install a cumulative branch release at or above 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 or 7.161.20, as applicable, and confirm current vendor guidance for their supported branch.

Operational response

  1. Restrict external access before remediation.
  2. Preserve Access and Artifactory logs, database state and relevant filesystem evidence.
  3. Hunt for unusual administrative users, token creation, Groovy plugins, successful /registry/join requests and the trailing-slash token sequence.
  4. Rotate administrative tokens, join keys, SSH material and secrets accessible from the repository environment.
  5. Independently validate high-value artifacts built, promoted or released during the suspected exposure window.
  6. If compromise is established—or repository integrity cannot be demonstrated—rebuild from trusted media and restore artifacts from validated provenance.

CISA added CVE-2026-82329 on September 2 with a September 5 remediation date. CVE-2026-42016 and CVE-2026-42018 were added September 11 with a September 25 date. These are distinct remediation queues and should not be collapsed into one deadline.

Evidence: Vendor advisories, CVE records, CISA dated alerts and incident-response observations from multiple self-hosted environments.

Attribution: Multiple actors are reported. No single publicly verified campaign or sponsor explains all activity.

Confidence: High for exploitation and the observed technical paths; moderate for the full victim population and actor relationships.

Uncertainty: Public reporting does not establish how many environments were successfully compromised or whether every observed post-exploitation payload used the same entry path.

Sources: [A1] JFrog Security Advisories; [A2] Wiz, “Artifactory Under Attack,” September 10, corrected September 11; [A3–A4] CISA dated alerts; [A5–A7] CVE records.


2. RED — GitLab CVE-2026-85706 reaches its CISA remediation date

CVE-2026-85706 is an unauthenticated path-traversal vulnerability in the GitLab repository commits API. Under affected conditions, an external attacker can read arbitrary server files. GitLab assigned the issue a CVSS score of 10.0.

Affected self-managed GitLab Community Edition and Enterprise Edition releases are:

  • 18.7 through versions before 19.1.8
  • 19.2 through versions before 19.2.6
  • 19.3 through versions before 19.3.2

The fixed releases are 19.1.8, 19.2.6 and 19.3.2. GitLab.com was patched by the vendor, and GitLab Dedicated customers do not require customer-side remediation for this issue. Self-managed installations must be upgraded.

The patch includes database migrations. Single-node deployments should plan for downtime; multi-node environments should follow GitLab’s zero-downtime procedure. Version 19.3.2 includes post-deployment migrations.

CISA added the vulnerability on September 11 with a September 14 remediation date. Public research recorded exploitation attempts or probing beginning September 11. The available public evidence supports active exploitation risk, but it does not identify a verified victim list or demonstrate successful data theft at every probed address.

Operational response

  • Upgrade first, then validate the running application and database-migration state.
  • Search web and API logs for unusual POST requests to /api/v4/projects/{id}/repository/commits/, particularly requests containing file.path.
  • Review administrative changes, deploy keys, access tokens, runners, pipelines and artifact activity.
  • Rotate credentials and secrets that could plausibly have been read from the GitLab host.
  • Treat unusual file-read requests as incident-response events, not routine vulnerability scans.

Evidence: GitLab’s patch release and affected-version statement; CISA’s dated exploitation alert; public technical analysis and observed internet activity.

Attribution: Unknown. No actor attribution is supported by the public evidence reviewed.

Confidence: High for vulnerability scope, fixed versions and exploitation designation; moderate for the interpretation of public scanning as successful exploitation.

Uncertainty: Public telemetry does not disclose the number of successful compromises or which files were obtained from any particular organization.

Sources: [B1] GitLab patch release, September 10; [B2] CISA dated alert, September 11; [B3] watchTowr technical analysis; [B4] The Hacker News exploitation report; [B5] CVE record; [B6] Canadian Centre for Cyber Security advisory.


3. RED — ScreenConnect requires client remediation, not just a server upgrade

CVE-2026-84869 affects ConnectWise ScreenConnect versions before 26.6.5. ConnectWise assigns it CVSS 9.9 and maps it to missing authorization and privilege-management weaknesses.

This is a client-side authorization failure. Under qualifying conditions, an actor with an active remote session and limited privileges can transfer or execute files without the expected authorization or host confirmation. It should not be described as unauthenticated, pre-authentication server RCE.

ConnectWise Cloud has been updated. Cloud customers must still reinstall affected host clients and update access agents. On-premises operators must upgrade to 26.6.5; ConnectWise states that direct upgrades require an installation already on 25.4 or later.

As a temporary control, disable TransferFiles for every applicable role and session group. This reduces exposure but does not replace the upgrade and client redeployment.

CISA added CVE-2026-84869 on September 11 with a September 14 remediation date. Huntress separately documented social-engineering incidents involving rogue or modified ScreenConnect clients that spawned wscript.exe, executed scripts named 1.vbs through 4.vbs, and established a WindowsServiceHost Run-key persistence mechanism. Modified clients reportedly propagated scripts to subsequently connected systems.

The Huntress campaign and the CISA exploitation designation are related defensive signals, but the public record does not prove that every reported “worm-like” event exploited CVE-2026-84869. Initial access in at least one documented case involved Quick Assist and social engineering.

Operational response

  • Measure remediation by connected client and access-agent version, not server version alone.
  • Disable file transfer until compliant client coverage is confirmed.
  • Hunt for wscript.exe, the numbered VBS files, WindowsServiceHost.vbs, related Run keys and ScreenConnect RunFiles/RanFiles audit events.
  • Review local users, ScreenConnect roles, password changes, MFA state and remote-session history.
  • Isolate and rebuild systems where unauthorized scripts or modified clients are confirmed.

Evidence: ConnectWise’s bulletin, CVE record, CISA’s dated exploitation alert, Huntress incident observations and NHS England’s cyber alert.

Attribution: Unknown. The reported social-engineering infrastructure does not provide reliable sponsor attribution.

Confidence: High for affected versions, remediation requirements and CISA exploitation status; moderate for the extent to which the vulnerability powered the observed propagation behavior.

Uncertainty: Public sources do not establish a complete victim count or a uniform initial-access method.

Sources: [C1] ConnectWise security bulletin, September 8; [C2] CISA dated alert, September 11; [C3] Huntress campaign analysis; [C4] NHS England cyber alert; [C5] CVE record.


4. RED where installed — Sogou Input Method chain delivered the GRAYRABBIT backdoor

Gen Threat Labs disclosed active exploitation of CVE-2026-51990 in Tencent’s Sogou Input Method for Windows.

The chain begins with an unsafe sgbiz: protocol handler implemented by biz_helper.exe. An attacker-controlled URL can be opened in a bundled Chromium Embedded Framework webview that Gen identified as CEF 80.1.16 / Chromium 80.0.3987.163, running without sandboxing and with web-security controls disabled.

The campaign then exploited CVE-2021-38003, a previously patched Chromium vulnerability affecting Chrome versions before 95.0.4638.69, to achieve code execution and deliver the GRAYRABBIT backdoor. Tencent characterized the chain as requiring a victim click and browser authorization prompt; Gen described no further interaction after the malicious link was accepted.

Gen reported the issue to Tencent on April 9. Tencent released Sogou Input Method 16.3.0.3498 on April 21 and told the researchers that it was deployed through automatic update. The fix validates HTTPS and restricts destinations to approved suffixes. Gen reports that the underlying bundled CEF remains obsolete, unsandboxed and configured without normal web-security controls.

Operational response

  • Verify installations are 16.3.0.3498 or later; do not assume automatic updating succeeded.
  • Remove Sogou Input Method from systems without a documented operational need.
  • Hunt for sgbiz: activations, SGMyInput.exe launches using -page=skincenter -url=, and suspicious 7-Zip components in public document directories.
  • Block and investigate connections to mail.uaiubifas[.]top, noht1ng[.]top and 8.218.50[.]207.
  • Consider application-control restrictions on custom-protocol handlers because the residual embedded-browser configuration leaves additional attack surface.

Gen associates the operation with UNC3569, a People’s Republic of China–nexus cluster previously documented by Google, and reports targeting across government, education, technology and finance, with concentration in East and Southeast Asia. This is a private-sector attribution assessment; the disclosure does not constitute a new government attribution.

Evidence: Gen’s technical disclosure, CVE record and corroborating reporting.

Attribution: Moderate confidence in Gen’s UNC3569/PRC-nexus assessment; no stronger public attribution was identified.

Confidence: High for the vulnerability chain, fixed Sogou version and malware delivery; moderate for the breadth and duration of the campaign.

Uncertainty: The number of compromised endpoints and the extent of post-compromise operations remain undisclosed.

Sources: [D1] Gen Threat Labs technical disclosure, September 10; [D2] CVE record; [D3] BleepingComputer report.


Defensive Posture Changes


Move from patch verification to trust verification

For GitLab and Artifactory, confirming a fixed version is only the first gate. The second is determining whether an attacker accessed credentials, changed administrative state or altered code and artifacts before remediation.

Organizations should establish a bounded exposure window for each system and validate:

  • Administrative accounts and privilege changes
  • Tokens, keys, secrets and federation material
  • Repository, build, package and release activity
  • Plugins, runners, hooks and automation
  • Artifacts promoted to production or distributed to customers
  • Log completeness and time synchronization

Measure ScreenConnect at the endpoint

A patched ScreenConnect server does not prove that every host client or unattended access agent has been replaced. Require version-level client coverage reporting and reconcile it against the asset inventory.

Preserve evidence before rotating everything

Credential rotation can erase useful temporal relationships. Preserve logs and relevant state first where operationally safe, then revoke or rotate exposed tokens, join keys, SSH keys and service credentials.

Treat published indicators as leads

Domains, IP addresses, file names and URL patterns are defensive pivots—not standalone proof of compromise. Correlate them with process lineage, authenticated identity, network timing and administrative changes.


Regional and Sector Pulse


  • North America: GitLab, Artifactory and ScreenConnect risk is installation-driven rather than region-specific. The BlueMoon browser/Windows chain remains relevant to previously reported targeting of US NGOs, mining, commodity-trading and aerospace organizations.
  • China and the wider Indo-Pacific: The Sogou chain has the clearest regional concentration. Gen reports UNC3569 activity centered on East and Southeast Asia, while also identifying targets elsewhere. No separate India-specific development was independently verified by the cutoff.
  • Europe: The EU Cyber Resilience Act’s vulnerability and severe-incident reporting provisions became applicable on September 11, 2026. Product manufacturers and affected open-source stewards should ensure that this week’s exploitation findings enter the appropriate product-security reporting process.
  • Middle East: The reported Houthi seizure of the Greater and Lesser Hanish islands adds physical monitoring requirements around Red Sea communications and shipping routes. No related cyber disruption or causal cyber linkage was verified.
  • Latin America and the Caribbean, Africa and Russia: No independently verified, region-specific campaign change tied to today’s four principal vulnerabilities was identified by the cutoff. Organizations remain exposed according to installed products and internet reachability, not geography alone.

Vulnerability and Supplier Watchlist


StatusProduct / chainRequired stateDeadline or trigger
REDJFrog Artifactory — CVE-2026-42016, CVE-2026-42018Cumulative fixed branch release plus forensic and provenance reviewCISA date: September 25
RED—overdueJFrog Artifactory — CVE-2026-82329Fixed release plus compromise assessmentCISA date passed September 5
RED—todayGitLab — CVE-2026-8570619.1.8, 19.2.6, 19.3.2 or later applicable releaseCISA date: September 14
RED—todayScreenConnect — CVE-2026-8486926.6.5; verify host clients and access agentsCISA date: September 14
RED where installedSogou Input Method — CVE-2026-5199016.3.0.3498 or later; remove if unnecessaryImmediate
RED—overdueMikroTik RouterOS — CVE-2026-67277, CVE-2026-860607.24.2 stable, 7.23.4 long-term, 6.49.21 long-term or later applicable releaseCISA date passed September 13
RED carry-forwardBlueMoon — CVE-2026-85046, CVE-2026-87491, CVE-2026-85880Browser-vendor builds carrying Chromium fixes plus Microsoft September security updatesCISA dates: September 22–23

MikroTik’s CVE-2026-67276 SSH public-key authentication bypass also remains important because CERT Polska observed it in an active chain with CVE-2026-86060. CISA’s cited September 10 addition covered CVE-2026-67277 and CVE-2026-86060, not CVE-2026-67276.

For BlueMoon, Google’s Chrome version numbers should not be applied mechanically to Edge, Brave or other Chromium-derived browsers. Verify that each browser vendor’s installed build contains the relevant upstream fixes.

Outlook and Uncertainty


Over the next 24–72 hours, watch for:

  • Additional Artifactory infrastructure, payloads and victim disclosures
  • Evidence distinguishing GitLab probing from confirmed file theft
  • Clarification of how frequently CVE-2026-84869 was used in the documented ScreenConnect campaigns
  • New GRAYRABBIT indicators or evidence of exploitation outside the reported Sogou population
  • Vendor advisories that revise fixed releases or required post-upgrade actions

The strongest conclusion is operational: administrative infrastructure exposed to these vulnerabilities must not be declared safe solely because a patch installed successfully. Trust must be re-established across identities, tokens, configuration, automation and artifacts.


Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.

Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.


Source Register — September 14, 2026

The generic CISA homepage and KEV catalog URL are intentionally omitted. CISA references below point to dated news-alert pages and are paired with vendor, researcher or national-CERT sources.

A. JFrog Artifactory

A1 — JFrog Security Advisories

https://docs.jfrog.com/releases/docs/jfrog-security-advisories

A2 — Wiz: Artifactory Under Attack

https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201

A3 — CISA September 11 dated alert

https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

A4 — CISA September 2 dated alert

https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog

A5 — CVE-2026-42016

https://www.cve.org/CVERecord?id=CVE-2026-42016

A6 — CVE-2026-42018

https://www.cve.org/CVERecord?id=CVE-2026-42018

A7 — CVE-2026-82329

https://www.cve.org/CVERecord?id=CVE-2026-82329

B. GitLab

B1 — GitLab patch release 19.3.2

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

B2 — CISA September 11 GitLab alert

https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog

B3 — watchTowr technical analysis

https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/

B4 — The Hacker News exploitation report

https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html

B5 — CVE-2026-85706

https://www.cve.org/CVERecord?id=CVE-2026-85706

B6 — Canadian Centre for Cyber Security advisory AV26-917

https://www.cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917

C. ConnectWise ScreenConnect

C1 — ConnectWise September 8 security bulletin

https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin

C2 — CISA September 11 dated alert

https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

C3 — Huntress: Rogue ScreenConnect Installations

https://www.huntress.com/blog/rogue-screenconnect-installations

C4 — NHS England Cyber Alert CC-4848

https://digital.nhs.uk/cyber-alerts/2026/cc-4848

C5 — CVE-2026-84869

https://www.cve.org/CVERecord?id=CVE-2026-84869

D. Sogou Input Method and GRAYRABBIT

D1 — Gen Threat Labs technical disclosure

https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou

D2 — CVE-2026-51990

https://www.cve.org/CVERecord?id=CVE-2026-51990

D3 — BleepingComputer corroborating report

https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/

E. MikroTik RouterOS carry-forward

E1 — MikroTik September 2026 vulnerability notice

https://mikrotik.com/supportsec/september-2026-vulnerability

E2 — CERT Polska exploitation analysis

https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/

E3 — CISA September 10 dated alert

https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog

E4 — CVE-2026-67276

https://www.cve.org/CVERecord?id=CVE-2026-67276

E5 — CVE-2026-86060

https://www.cve.org/CVERecord?id=CVE-2026-86060

E6 — CVE-2026-67277

https://www.cve.org/CVERecord?id=CVE-2026-67277

F. BlueMoon carry-forward

F1 — Proofpoint BlueMoon analysis

https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit

F2 — Chrome stable update addressing CVE-2026-85046

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html

F3 — Chrome stable update addressing CVE-2026-87491

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

F4 — Microsoft CVE-2026-85880 record

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880

F5 — CVE-2026-85046

https://www.cve.org/CVERecord?id=CVE-2026-85046

F6 — CVE-2026-87491

https://www.cve.org/CVERecord?id=CVE-2026-87491

F7 — CVE-2026-85880

https://www.cve.org/CVERecord?id=CVE-2026-85880

G. European regulatory context

G1 — EU Cyber Resilience Act, Regulation (EU) 2024/2847

https://eur-lex.europa.eu/eli/reg/2024/2847/oj

H. Middle East physical-risk context

H1 — Associated Press report on the Hanish islands

https://apnews.com/article/b95a5a6c73a26bbbb1caddcbf365ca62