2026-09-17

This week

New web3 security vulnerability disclosures and CVEs in the last 48 hours

Over the past 48 hours, several critical vulnerabilities have been disclosed across various web applications and protocols that could significantly impact security. These include a path traversal vuln…

RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours

RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs in the Last 48 Hours

Summary

Over the past 48 hours, several critical vulnerabilities have been disclosed across various web applications and protocols that could significantly impact security. These include a path traversal vulnerability in GitLab, improper authentication issues in JFrog Artifactory, and missing authentication flaws in MikroTik RouterOS, among others. The disclosures highlight ongoing challenges in securing web services and the importance of timely patching and responsible disclosure practices.

Key Developments

  • 2026-09-11 — GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability (CVE-2026-85706) that allows an unauthenticated user to read arbitrary files due to improper path confinement and missing authentication enforcement in the repository commits API. CISA KEV Catalog
  • 2026-09-11 — JFrog Artifactory has an improper authentication vulnerability (CVE-2026-42018) that could return an internal anonymous-user token to unauthenticated callers when anonymous access is disabled, potentially exposing sensitive resources. CISA KEV Catalog
  • 2026-09-11 — Another JFrog Artifactory vulnerability (CVE-2026-42016) involves incorrect authorization allowing privilege escalation due to validation checks of token signature and issuer rather than scope. CISA KEV Catalog
  • 2026-09-11 — ConnectWise ScreenConnect (CVE-2026-84869) suffers from improper privilege management and missing authorization, potentially enabling file transfers and execution through active remote sessions without authorization. CISA KEV Catalog
  • 2026-09-10 — MikroTik RouterOS (CVE-2026-67277) has a missing authentication for critical functions, leading to kernel memory disclosure and denial of service in the btest service. CISA KEV Catalog
  • 2026-09-10 — An additional MikroTik RouterOS vulnerability (CVE-2026-86060) involves improper neutralization of argument delimiters in commands, enabling privilege escalation via trusted policy mask changes. CISA KEV Catalog
  • 2026-09-09 — Cisco Secure Firewall Management Center and Security Cloud Control (CVE-2026-20079) feature an authentication bypass using alternate paths or channels, allowing unauthenticated remote attackers to execute scripts for root access. Cisco Security Advisory
  • 2026-09-09 — Google Chromium V8 (CVE-2026-87491) has an out-of-bounds write vulnerability, enabling remote attackers to execute arbitrary code via crafted HTML pages in supported browsers. NVD

Sources