Compiled from 52 monitored sources · 1231 articles reviewed
Today’s Briefing
CISA added four vulnerabilities to the Known Exploited Vulnerabilities catalog today: CVE-2026-85706, a path traversal flaw in GitLab Community and Enterprise Edition that permits unauthenticated arbitrary file reads; CVE-2026-84869 in ConnectWise ScreenConnect, allowing unauthorised file transfer and execution through active remote sessions; and CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, both authentication and authorisation bypasses enabling privilege escalation and exposure of resources when anonymous access is disabled. The NHS Digital alert flags CVE-2026-0310 in Palo Alto Networks PAN-OS, rated medium severity, which may permit denial of service or root-level arbitrary code execution. CISA also published an advisory for NextGen Healthcare Mirth Connect versions up to 4.7.1, covering three vulnerabilities that could enable data exfiltration or denial of service.
Top Stories
- CISA Adds One Known Exploited Vulnerability to Catalog
- CC-4850 - Palo Alto Networks Releases Security Advisory for PAN-OS
- NextGen Healthcare Mirth Connect
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.