Critical Vulnerabilities Exploited as CISA Updates KEV Catalog
Multiple critical flaws in JFrog, GitLab, and Dell storage are under active attack while CISA adds them to its exploited vulnerabilities list.
The TechMap Live reporter · · 2 min read · from 10 reports

Listen to this briefing
About 1 min to listen
Read the transcript
We're seeing a cluster of critical vulnerabilities under active exploitation right now. JFrog Artifactory, the software supply chain platform out of Israel, is being hit through a chained exploit tracked as CVE-2026-82329. At the same time, GitLab pushed emergency patches for a maximum-severity path traversal flaw on September tenth, and CISA confirmed attackers are already using it. The agency added both to its Known Exploited Vulnerabilities catalog along with two ConnectWise ScreenConnect flaws. Dell also dropped patches for eleven holes in its ObjectScale and ECS storage gear, several rated ten out of ten. On the incident side, a Taiwanese biotech firm called Darul Derm took a hit to internal systems but says operations and data are fine. And NATO says it stopped a Russian attempt to sever a fourteen-hundred-kilometer NASA undersea cable using a no-trace cutting tool. Elsewhere, Xiaomi opened the global beta for HyperOS 4 on seven flagships, Sam Altman and Elon Musk backed Dario Amodei's call to slow frontier AI development, and a battery drone just broke the endurance record at a U.S. Army test range.
Active exploitation of critical flaws
Attackers are chaining multiple security flaws to exploit CVE-2026-82329 in JFrog Artifactory, a software supply chain platform based in Ramat Gan, Israel. The U.S. Cybersecurity and Infrastructure Security Agency added this vulnerability alongside two actively exploited flaws in ConnectWise ScreenConnect to its Known Exploited Vulnerabilities catalog on September 11.
GitLab disclosed and patched a CVSS 10.0 path traversal vulnerability, CVE-2026-85706, on September 10, releasing versions 19.1.8, 19.2.6, and 19.3.2. CISA confirmed active exploitation of this flaw the same week and added it to the KEV list. The vulnerability allows unauthenticated remote file read across GitLab instances.
Dell released patches on September 11 for eleven vulnerabilities in its ObjectScale and ECS object storage platforms, including critical CVSS 10.0 flaws that allow remote code execution. The patches cover both on-premises storage systems used by enterprises for large-scale data management.
Notable cyber incidents reported
Taiwanese biotech medical company Darul Derm reported a cyberattack on part of its internal information systems. The company, listed as 6523, assessed no major impact on operations or data leakage from the incident discovered in Taipei.
NATO allies prevented Russia from cutting a 1,400-kilometer NASA Near Space Network cable using a tool designed to leave no traceable fingerprints. The attempted sabotage was blocked in Brussels, highlighting ongoing threats to undersea critical infrastructure.
Other technology developments
Xiaomi launched the global beta program for HyperOS 4 across seven flagship smartphone models. The rollout begins from Beijing as the company tests its next major operating system update with users worldwide.
OpenAI chief executive Sam Altman and Elon Musk publicly backed Anthropic chief executive Dario Amodei's call for the AI industry to slow down frontier model development. The statement from San Francisco marks rare alignment between the tech leaders on AI safety pacing.
A battery-powered drone set a new world endurance record using a propulsion system assembled at a U.S. Army depot at Aberdeen Proving Ground. The achievement demonstrates advances in electric flight duration for uncrewed systems.
Questions people ask
Which vulnerabilities did CISA add to its exploited list this week?
CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 11: CVE-2026-82329 in JFrog Artifactory, two flaws in ConnectWise ScreenConnect, and GitLab's CVE-2026-85706 path traversal vulnerability.
What patches did Dell release for its storage platforms?
Dell released patches on September 11 for eleven vulnerabilities in ObjectScale and ECS object storage platforms, including critical CVSS 10.0 flaws that allow remote code execution.
What was the NATO incident involving a NASA cable?
NATO allies prevented Russia from cutting a 1,400-kilometer NASA Near Space Network cable using a tool that leaves no traceable fingerprints. The attempted sabotage was blocked in Brussels.
The events in this briefing
Every event summarised above, in the order it was reported. Each one links to its own page and to the outlet that reported it, so any figure here can be checked against its source.
- JFrog Artifactory actively exploited via critical vulnerability · iThome Taiwan
- CISA adds actively exploited vulnerabilities in ConnectWise ScreenConnect and JFrog Artifactory to KEV catalog · iThome Taiwan
- CISA adds GitLab path traversal flaw to exploited vulnerabilities list · iThome Taiwan
- Dell patches critical ObjectScale and ECS storage vulnerabilities · iThome Taiwan
- Xiaomi launches global HyperOS 4 beta for seven flagship phones · Zoomit
- Darul Derm suffers partial internal systems cyberattack · iThome Taiwan
- Altman and Musk back Amodei's call to slow AI frontier development · SiliconANGLE
- Battery-powered drone sets world endurance record · Interesting Engineering
- GitLab patches critical path traversal vulnerability CVE-2026-85706 · iThome Taiwan
- NATO blocks Russian sabotage of undersea cable · TechRadar
This briefing was written by an automated reporter from 10 event reports already published on this site. It contains no original reporting, and no figures beyond those in the events listed above.
More briefings
- Robotics surge and new tech launches as September events stack up
- Tech map update: payment shifts, AI labs, and cyber alerts
- Tech update: AI defence, phone teardowns and security alerts
- Tech updates: Apple foldable yield, crypto theft, and security patches
- AI security tests and software updates shape tech week