GitLab CVSS 10.0 Path Traversal Exploited Within 24 Hours of Disclosure. GitLab patched two critical flaws this week: CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal allowing arbitrary file reads (including credentials), and CVE-2026-87719, a CVSS 9.9 insecure deserialization bug in the GraphQL subscription serializer. CISA added CVE-2026-85706 to its KEV catalog after WatchTowr Labs confirmed internet-wide probing began the day after disclosure. Learn more
JFrog Artifactory Flaws Chained to Deploy Rust Backdoor in Under Five Minutes. Attackers are actively chaining CVE-2026-42018 and CVE-2026-42016 in self-hosted Artifactory instances to escalate from anonymous-user tokens to full administrator access, then deploy a custom Rust backdoor. Both CVEs, along with a ConnectWise ScreenConnect flaw, were added to the CISA KEV catalog this week with mandatory federal patching deadlines.
Check Point VPN Critical 9.8 RCE Flaws Draw Imminent Exploitation Warning. Check Point disclosed CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, enabling unauthenticated remote code execution against Quantum Security Gateways and Management Servers. While Check Point reports no confirmed exploitation yet, the Dutch NCSC issued a separate warning calling exploitation imminent. Learn more
BlueMoon Exploit Kit Chains Windows and Chrome Zero-Days for Espionage. A new exploit kit called BlueMoon chains unpatched Chrome V8 and Windows kernel zero-days to achieve sandbox escape and privilege escalation. Multiple Chinese state-sponsored groups including Violet Typhoon and JungleBamboo have already adopted the kit against NGOs and government targets, raising concern that financially motivated actors will follow. Learn more
Key Takeaway
Patch GitLab, Artifactory, Check Point VPN, Cisco FMC, NetScaler ADC, and MikroTik RouterOS this week; all carry active exploitation evidence and KEV mandates.
