Mathew Potter
Security Analyst
Calendar reminders matter when CISA sets them. September 14, 2026 is the due date for two actively exploited flaws that hit the tools security teams rely on: GitLab self-managed instances and ConnectWise ScreenConnect clients.
The GitLab issue is a CVSS 10.0 path traversal in the repository commits API. Unauthenticated attackers can read arbitrary server files. Public reporting tied the bug to probes within hours of disclosure. CISA added it to KEV on September 11 with forensic triage required under BOD 26-04.
That triage language is the part teams skip. Upgrading to 19.1.8, 19.2.6, or 19.3.2 closes the hole going forward. It does not tell you whether someone already pulled secrets from disk. Hunt POST traffic to the commits API, review logs since September 10, and rotate CI variables, deploy tokens, and SSH keys if exposure is plausible.
ConnectWise fixed CVE-2026-84869 in ScreenConnect 26.6.5. The flaw is client-side: under some conditions an active remote session can transfer and run files without proper host confirmation. Huntress documented worm-like abuse where rogue clients infected new machines as technicians connected.
Remediation means upgrading the server and refreshing host clients and access agents. It also means checking audit logs for RunFiles or RanFiles executed from guest processes. ConnectWise recommends removing TransferFiles permissions as a temporary brake if you cannot finish upgrades immediately.
JFrog Artifactory chained flaws carry a September 25 federal due date. MikroTik RouterOS entries landed with September 13 deadlines for some CVEs. If your vulnerability program only tracks Windows, these dates are a reminder that dev tools, MSP software, and edge routers share the same calendar.
KEV dates are prioritization signals for every organization, not only federal agencies. Forensic Five helps Canadian teams scan external exposure, verify patch posture, and produce written assessment output. From St. Albert, Alberta. Scoped work, clear limits stated up front.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.