|
1 | 1 | { |
2 | 2 | "title": "CISA Catalog of Known Exploited Vulnerabilities", |
3 | | - "catalogVersion": "2026.09.10", |
4 | | - "dateReleased": "2026-09-10T19:00:05.1949Z", |
5 | | - "count": 1705, |
| 3 | + "catalogVersion": "2026.09.11", |
| 4 | + "dateReleased": "2026-09-11T19:32:16.8993Z", |
| 5 | + "count": 1709, |
6 | 6 | "vulnerabilities": [ |
| 7 | + { |
| 8 | + "cveID": "CVE-2026-84869", |
| 9 | + "vendorProject": "ConnectWise", |
| 10 | + "product": "ScreenConnect", |
| 11 | + "vulnerabilityName": "ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability", |
| 12 | + "dateAdded": "2026-09-11", |
| 13 | + "shortDescription": "ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.", |
| 14 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 15 | + "dueDate": "2026-09-14", |
| 16 | + "knownRansomwareCampaignUse": "Unknown", |
| 17 | + "forensicTriage": "Yes", |
| 18 | + "notes": "https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-09-08-screenconnect-bulletin ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-84869", |
| 19 | + "cwes": [ |
| 20 | + "CWE-269", |
| 21 | + "CWE-862" |
| 22 | + ] |
| 23 | + }, |
| 24 | + { |
| 25 | + "cveID": "CVE-2026-42016", |
| 26 | + "vendorProject": "JFrog", |
| 27 | + "product": "Artifactory", |
| 28 | + "vulnerabilityName": "JFrog Artifactory Incorrect Authorization Vulnerability", |
| 29 | + "dateAdded": "2026-09-11", |
| 30 | + "shortDescription": "JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature\/issuer and not the token\u2019s scope.", |
| 31 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 32 | + "dueDate": "2026-09-25", |
| 33 | + "knownRansomwareCampaignUse": "Unknown", |
| 34 | + "forensicTriage": "No", |
| 35 | + "notes": "https:\/\/docs.jfrog.com\/releases\/docs\/jfrog-security-advisories ; https:\/\/docs.jfrog.com\/releases\/docs\/artifactory-self-managed-releases ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-42016", |
| 36 | + "cwes": [ |
| 37 | + "CWE-863" |
| 38 | + ] |
| 39 | + }, |
| 40 | + { |
| 41 | + "cveID": "CVE-2026-42018", |
| 42 | + "vendorProject": "JFrog", |
| 43 | + "product": "Artifactory", |
| 44 | + "vulnerabilityName": "JFrog Artifactory Improper Authentication Vulnerability", |
| 45 | + "dateAdded": "2026-09-11", |
| 46 | + "shortDescription": "JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.", |
| 47 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 48 | + "dueDate": "2026-09-25", |
| 49 | + "knownRansomwareCampaignUse": "Unknown", |
| 50 | + "forensicTriage": "No", |
| 51 | + "notes": "https:\/\/docs.jfrog.com\/releases\/docs\/jfrog-security-advisories ; https:\/\/docs.jfrog.com\/releases\/docs\/artifactory-self-managed-releases ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-42018", |
| 52 | + "cwes": [ |
| 53 | + "CWE-287" |
| 54 | + ] |
| 55 | + }, |
| 56 | + { |
| 57 | + "cveID": "CVE-2026-85706", |
| 58 | + "vendorProject": "GitLab", |
| 59 | + "product": "Community Edition and Enterprise Edition", |
| 60 | + "vulnerabilityName": "GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability", |
| 61 | + "dateAdded": "2026-09-11", |
| 62 | + "shortDescription": "GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.", |
| 63 | + "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
| 64 | + "dueDate": "2026-09-14", |
| 65 | + "knownRansomwareCampaignUse": "Unknown", |
| 66 | + "forensicTriage": "Yes", |
| 67 | + "notes": "https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-3-2-released\/ ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-85706", |
| 68 | + "cwes": [ |
| 69 | + "CWE-35" |
| 70 | + ] |
| 71 | + }, |
7 | 72 | { |
8 | 73 | "cveID": "CVE-2026-86060", |
9 | 74 | "vendorProject": "MikroTik", |
|
589 | 654 | "shortDescription": "Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.", |
590 | 655 | "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.", |
591 | 656 | "dueDate": "2026-08-21", |
592 | | - "knownRansomwareCampaignUse": "Unknown", |
| 657 | + "knownRansomwareCampaignUse": "Known", |
593 | 658 | "forensicTriage": "Yes", |
594 | 659 | "notes": "https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/38017 ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-59310", |
595 | 660 | "cwes": [ |
|
0 commit comments