CVE Digest — September 11, 2026
12 CVE
4 KEV
Digest for September 11, 2026: 4 new entries in the CISA KEV catalog and 8 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- Risolte vulnerabilità in GitLab CE/EE
- Rclone: PoC pubblici per lo sfruttamento delle CVE-2026-88018, CVE-2026-88044, CVE-2026-88045, CVE-2026-88016 e CVE-202…
- Sanate vulnerabilità in strongSwan
- Rilevate vulnerabilità in prodotti MongoDB
- Risolte vulnerabilità in MISP Project
- Risolta vulnerabilità in Hikvision HikCentral Access Control
- Aggiornamento per Autodesk Fusion
- Rilevata vulnerabilità in Craft CMS
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-84869 KEV | ConnectWise ScreenConnect | – | Unknown | ConnectWise ScreenConnect is newly added to CISA KEV. It has improper privilege management and missing authorization flaws that may let an attacker transfer files and execute code through active remote sessions without authorization or host confirmation. Apply vendor mitigations… | |
| CVE-2026-42016 KEV | JFrog Artifactory | – | Unknown | JFrog Artifactory is newly added to CISA KEV. An incorrect authorization flaw allows privilege escalation because token validation checks signature/issuer instead of the token’s scope. Apply vendor mitigations per BOD 26-04 guidance. | |
| CVE-2026-42018 KEV | JFrog Artifactory | – | Unknown | JFrog Artifactory is newly added to CISA KEV. An improper authentication flaw can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled, potentially exposing sensitive resources. Apply vendor mitigations per BOD 26-04. | |
| CVE-2026-85706 KEV | GitLab Community Edition and Enterprise Edition | – | Unknown | GitLab CE and EE are newly added to CISA KEV. A path traversal in the repository commits API lets an unauthenticated user read arbitrary files due to improper path confinement and missing authentication enforcement. Apply vendor mitigations per BOD 26-04. | |
| ee | – | – | Unknown | ACN advisory: security updates for GitLab, the software development lifecycle and project collaboration platform, fix several vulnerabilities, including 2 rated critical and 6 rated high severity. | |
| CVE-2026-88018 | – | – | Unknown | ACN advisory: public Proof of Concept (PoC) exploits are available for Rclone CVEs 2026-88018, 2026-88044, 2026-88045, 2026-88016 and 2026-88017. The vulnerabilities are already patched by the vendor, but prioritize updating to mitigate exploitation risk. | |
| sanate-vulnerabilita-in-strongswan | – | – | Unknown | ACN advisory: multiple security vulnerabilities, including 4 rated high severity, have been fixed in strongSwan, the well-known open-source software for building VPN connections. | |
| rilevate-vulnerabilita-in-prodotti-mongodb-4 | – | – | Unknown | ACN advisory: security updates fix multiple vulnerabilities in MongoDB products, including 5 rated high severity. | |
| risolte-vulnerabilita-in-misp-project | – | – | Unknown | ACN advisory: security updates fix two vulnerabilities in MISP Project, the collaborative cyber threat intelligence platform, including one rated high severity. | |
| risolta-vulnerabilita-in-hikvision-hikcentral-access-control | – | – | Unknown | ACN advisory: Hikvision released a security update fixing a high severity vulnerability in HikCentral Access Control, the centralized access control management platform. | |
| aggiornamento-per-autodesk-fusion | – | – | Unknown | ACN advisory: Autodesk fixed a high severity vulnerability in Fusion. If exploited, it could allow an attacker to modify data without authorization and/or access sensitive information on affected systems. | |
| rilevata-vulnerabilita-in-craft-cms-1 | – | – | Unknown | ACN advisory: a high severity vulnerability was found in Craft CMS. If exploited, a remote attacker authenticated with limited privileges could execute arbitrary code on affected systems. |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.