September 14 KEV deadlines: GitLab and ScreenConnect are due today
Vulnerability Management

September 14 KEV deadlines: GitLab and ScreenConnect are due today

Mathew Potter

Security Analyst

September 14, 2026

Calendar reminders matter when CISA sets them. September 14, 2026 is the due date for two actively exploited flaws that hit the tools security teams rely on: GitLab self-managed instances and ConnectWise ScreenConnect clients.

GitLab CVE-2026-85706: patch plus prove you were not read

The GitLab issue is a CVSS 10.0 path traversal in the repository commits API. Unauthenticated attackers can read arbitrary server files. Public reporting tied the bug to probes within hours of disclosure. CISA added it to KEV on September 11 with forensic triage required under BOD 26-04.

That triage language is the part teams skip. Upgrading to 19.1.8, 19.2.6, or 19.3.2 closes the hole going forward. It does not tell you whether someone already pulled secrets from disk. Hunt POST traffic to the commits API, review logs since September 10, and rotate CI variables, deploy tokens, and SSH keys if exposure is plausible.

ScreenConnect CVE-2026-84869: server version is not enough

ConnectWise fixed CVE-2026-84869 in ScreenConnect 26.6.5. The flaw is client-side: under some conditions an active remote session can transfer and run files without proper host confirmation. Huntress documented worm-like abuse where rogue clients infected new machines as technicians connected.

Remediation means upgrading the server and refreshing host clients and access agents. It also means checking audit logs for RunFiles or RanFiles executed from guest processes. ConnectWise recommends removing TransferFiles permissions as a temporary brake if you cannot finish upgrades immediately.

Still on deck this month

JFrog Artifactory chained flaws carry a September 25 federal due date. MikroTik RouterOS entries landed with September 13 deadlines for some CVEs. If your vulnerability program only tracks Windows, these dates are a reminder that dev tools, MSP software, and edge routers share the same calendar.

A one-page checklist

  • Confirm GitLab version and patch level. Run vendor IOC guidance if available.
  • Confirm ScreenConnect is 26.6.5 or newer on server and endpoints.
  • Document patch evidence for insurance and client questionnaires.
  • Schedule Artifactory upgrades before September 25 if you self-host.
  • Revisit internet exposure on GitLab and Artifactory management URLs.

Bottom line

KEV dates are prioritization signals for every organization, not only federal agencies. Forensic Five helps Canadian teams scan external exposure, verify patch posture, and produce written assessment output. From St. Albert, Alberta. Scoped work, clear limits stated up front.

Tags

CISA KEV GitLab ScreenConnect patch management forensic triage

Share This Article

About the Author

Mathew Potter

Security Analyst

Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.