Executive assessment
Today's brief leads with GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability — Community Edition and Enterprise Edition. All 10 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 leads because it is CRITICAL, has exploitation in the wild, and has fixed GitLab CE/EE releases available. Finding 02 should follow because it is also being exploited in the wild, with fixed RouterOS releases and exposure-reduction controls listed. Themes: In-the-wild exploitation of infrastructure software; Exposure reduction as interim control; Injection and input-validation flaws. Patch order: Finding 01 (CRITICAL GitLab path traversal vulnerability with exploitation in the wild and fixed CE/EE releases available); Finding 02 (HIGH RouterOS missing-authentication vulnerability with exploitation in the wild and fixed Long-term and Stable releases available); Finding 03 (HIGH Mirth Connect issue with PoC exploitation and a fix in 4.7.2 or later); Finding 05 (HIGH KissFFT vulnerabilities with PoC exploitation and fixed Ubuntu packages available).
Finding 01 — GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability — Community Edition and Enterprise Edition
What changed: CISA lists this GitLab Community Edition and Enterprise Edition path-traversal vulnerability in the Known Exploited Vulnerabilities catalog, grounding the active-exploitation status. Operators should apply the vendor mitigation referenced by the catalog and review affected GitLab exposure.
Technical evidence: CVE-2026-85706; CVSS v3.1 10; weakness CWE-22; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: If patching is not immediately possible, remove public access to the self-hosted GitLab instance. Monitor logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.path parameters. SecurityWeek reports that WatchTowr observed the first in-the-wild exploitation attempts one day after GitLab announced patches. ([docs.gitlab.com](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/), [watchtowr.com](https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/), [securityweek.com](https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/))
Affected: GitLab CE/EE versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. ([docs.gitlab.com](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/))
Fix: GitLab CE/EE 19.1.8, 19.2.6 and 19.3.2. ([watchtowr.com](https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/))
Action: Map CVE-2026-85706 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-85706)
Finding 02 — MikroTik RouterOS Missing Authentication for Critical Function Vulnerability — RouterOS
What changed: CISA lists a missing-authentication vulnerability in MikroTik RouterOS in the Known Exploited Vulnerabilities catalog. Internet-exposed RouterOS management surfaces require urgent inventory and remediation.
Technical evidence: CVE-2026-67277; CVSS v4.0 8.8; weakness CWE-306; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Until patching, disable exposed SSH, WWW/WWW-SSL and bandwidth-test services, or block access from outside trusted management networks. CISA reports CVE-2026-67277 was added to KEV based on evidence of active exploitation. ([cert.pl](https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/), [cisa.gov](https://www.cisa.gov/news-events/alerts/2026/09/10/cisa-adds-two-known-exploited-vulnerabilities-catalog), [cert.pl](https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve))
Affected: RouterOS 7.24 to before 7.24.2, 7.0.0 to before 7.23.4, and 6.0.0 to before 6.49.21. ([cert.pl](https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve))
Fix: RouterOS 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable). ([cert.pl](https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve))
Action: Map CVE-2026-67277 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-67277)
Finding 03 — Multiple vulnerabilities in NextGen Healthcare Mirth Connect
What changed: CISA reports SQL injection, XML external entity, and denial-of-service risks affecting Mirth Connect 4.7.1 and earlier. Successful exploitation may exfiltrate data or disrupt service.
Technical evidence: CVE-2026-82583; CVSS v3.1 8.3; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Minimise network exposure, keep affected systems off the public internet, and isolate them behind firewalls from business networks. Restrict or disable XSLT Transformer Steps that accept untrusted external input until patched. ([cisa.gov](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01), [ionix.io](https://www.ionix.io/threat-center/cve-2026-78224/), [seclists.org](https://seclists.org/oss-sec/2026/q3/715))
Fix: Mirth Connect 4.7.2 or later. ([cisa.gov](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01))
Panel assessment: Patch now, especially for any Mirth Connect instance reachable from the internet or processing untrusted input, because high-severity SQL injection, XXE, and denial-of-service flaws now have public end-to-end exploits and a fixed version is available. The practical attack path is crafted SQL or XML/XSLT input reaching Mirth Connect, with plausible outcomes of data exfiltration from data the platform can access or disruption of service and connected processing. (priority: patch now)
Action: Map CVE-2026-82583 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-01)
Finding 04 — Orthanc DICOM Server: Integer Overflow or Wraparound
What changed: CISA reports an integer-overflow flaw in Orthanc before 1.13.0 that an authenticated remote attacker can trigger with a crafted PNG or JPEG. Exploitation can write beyond a heap allocation and crash the DICOM server.
Technical evidence: CVE-2026-87020; CVSS v3.1 8.1; weakness CWE-190; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict network access to Orthanc instances to trusted hosts only and ensure they are not accessible from the internet. CISA reports no known public exploitation specifically targeting this vulnerability. ([cisa.gov](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02), [hipaajournal.com](https://www.hipaajournal.com/orthanc-dicom-server-vulnerability-denial-of-service/))
Affected: All Orthanc DICOM Server versions prior to 1.13.0. ([hipaajournal.com](https://www.hipaajournal.com/orthanc-dicom-server-vulnerability-denial-of-service/))
Fix: Version 1.13.0 and later versions. ([hipaajournal.com](https://www.hipaajournal.com/orthanc-dicom-server-vulnerability-denial-of-service/))
Panel assessment: Patch this week, prioritising any Orthanc instance reachable from untrusted networks: authentication and no known public exploitation reduce urgency, but the supported impact is a remote crash of a high-severity DICOM service flaw across all versions before 1.13.0. (priority: this week)
Action: Map CVE-2026-87020 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02)
Finding 05 — USN-8745-1: KissFFT vulnerabilities
What changed: Ubuntu fixed two KissFFT size-handling vulnerabilities affecting large transforms on 32-bit architectures and multidimensional transforms. Crafted input may crash applications or enable arbitrary code execution.
Technical evidence: CVE-2025-34297; CVSS v4.0 8.6; weakness CWE-190; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Before patching, bounds-check nfft and reject values above 536,870,912 on 32-bit systems; validate multidimensional FFT inputs so products do not approach INT_MAX. Temporarily disable affected FFT functionality if those checks cannot be enforced. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8745-1), [ubuntu.com](https://ubuntu.com/security/CVE-2026-41445), [github.com](https://github.com/mborgerding/kissfft/issues/120), +1 more)
Affected: The notice covers Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS; Ubuntu marks 25.10 as end-of-life and ignored. ([ubuntu.com](https://ubuntu.com/security/notices/USN-8745-1), [ubuntu.com](https://ubuntu.com/security/CVE-2026-41445))
Fix: Ubuntu kissfft packages are fixed in 131.1.0-2ubuntu0.1~esm1 for 22.04 LTS, 131.1.0-3ubuntu0.1~esm1 for 24.04 LTS and 131.1.0-4ubuntu0.1~esm1 for 26.04 LTS. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-41445))
Action: Map CVE-2025-34297 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8745-1)
Finding 06 — Host and event action script input is validated with a regex (set
What changed: Zabbix host and event action-script validation can be bypassed when administrator-defined regexes use anchors in multiline mode. An authenticated user can inject a newline and shell commands.
Technical evidence: CVE-2026-23920; CVSS v4.0 7.7; weakness CWE-78; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Replace ^ and $ anchors with \A and \z in affected regex validation until patching. ([support.zabbix.com](https://support.zabbix.com/browse/ZBX-27639), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-23920))
Affected: Zabbix Server and Proxy 7.0.0-7.0.21, 7.2.0-7.2.14 and 7.4.0-7.4.5. ([support.zabbix.com](https://support.zabbix.com/browse/ZBX-27639))
Fix: Zabbix 7.0.22, 7.2.15 and 7.4.6. ([support.zabbix.com](https://support.zabbix.com/browse/ZBX-27639))
Action: Map CVE-2026-23920 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-23920)
Finding 07 — A low privilege Zabbix user with API access can exploit a blind SQL injection
What changed: A low-privilege Zabbix user with API access can inject blind SQL through the sortfield parameter. Time-based extraction may expose database data and session identifiers, enabling administrator compromise.
Technical evidence: CVE-2026-23921; CVSS v4.0 8.7; weakness CWE-89; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Restrict API permissions to essential users and limit API endpoint exposure to trusted IP ranges. Monitor Zabbix API access logs for sortfield values containing SQL keywords and baseline response times for artificial delays. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-23921/), [support.zabbix.com](https://support.zabbix.com/browse/ZBX-27640))
Affected: Zabbix 7.0.0-7.0.21, 7.2.0-7.2.14 and 7.4.0-7.4.5. ([support.zabbix.com](https://support.zabbix.com/browse/ZBX-27640))
Fix: Zabbix 7.0.22, 7.2.15 and 7.4.6. ([support.zabbix.com](https://support.zabbix.com/browse/ZBX-27640))
Action: Map CVE-2026-23921 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-23921)
Finding 08 — SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed
What changed: SPIP before 4.4.18 contains a code-injection flaw in SQLite-backed installations because array-typed input can escape an internal quoted PHP context. An authenticated editor can send a crafted navigation request to execute operating-system commands in the web-server process; MySQL-backed installations are not affected.
Technical evidence: CVE-2026-66738; CVSS v4.0 7.7; weakness CWE-94; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict /ecrire/?exec=navigation so it is not reachable by untrusted users. CISA ADP Vulnrichment reports exploitation as 'none'. ([secalerts.co](https://secalerts.co/vulnerability/CVE-2026-66738), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-66738), [vulncheck.com](https://www.vulncheck.com/advisories/spip-code-injection-via-navigation-endpoint-on-sqlite), +2 more)
Affected: SQLite-backed SPIP versions before 4.4.18. ([vulncheck.com](https://www.vulncheck.com/advisories/spip-code-injection-via-navigation-endpoint-on-sqlite))
Fix: Upstream SPIP 4.4.18; Debian 13 (trixie) package 4.4.19+dfsg-0+deb13u1. ([blog.spip.net](https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html), [lists.debian.org](https://lists.debian.org/debian-security-announce/2026/msg00345.html))
Action: Map CVE-2026-66738 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-66738)
Finding 09 — GlobalProtect App: Local Privilege Escalation Vulnerabilities
What changed: Palo Alto Networks disclosed local privilege-escalation vulnerabilities in GlobalProtect App. Administrators should use the vendor's affected-version and fixed-release guidance to remediate managed endpoints.
Technical evidence: CVE-2026-0307; CVSS v4.0 5.9; weakness CWE-426; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: No known workarounds exist for this issue. Palo Alto Networks reports that it is not aware of any malicious exploitation. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0307))
Affected: Linux: GlobalProtect App 6.2.0 through 6.3.3-h14 and 6.0.0 through 6.0.14. macOS and Windows: 6.3.0 through 6.3.3-h14, 6.2.0 through 6.2.8-h13, and 6.0.0 through 6.0.14. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0307))
Fix: GlobalProtect App 6.3.3-h15 or later for Linux, macOS and Windows; 6.2.8-h14 or later for macOS and Windows; 6.0.15 or later for Linux, macOS and Windows. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0307))
Action: Map CVE-2026-0307 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0307)
Finding 10 — USN-8747-1: Beets vulnerability
What changed: Ubuntu reports that Beets improperly escaped untrusted media metadata in its web interface. An attacker may inject HTML or execute JavaScript in a user's browser.
Technical evidence: CVE-2026-42052; CVSS v4.0 6; weakness CWE-79; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Until patched, disable the web plugin; if it must run, bind it to 127.0.0.1 rather than all interfaces. ([beets.readthedocs.io](https://beets.readthedocs.io/en/stable/plugins/web.html), [tenable.com](https://www.tenable.com/plugins/nessus/344657), [api.github.com](https://api.github.com/advisories/GHSA-3gxm-wfjx-m847))
Affected: PyPI beets versions earlier than 2.10.0. ([api.github.com](https://api.github.com/advisories/GHSA-3gxm-wfjx-m847))
Fix: Upstream beets 2.10.0. ([api.github.com](https://api.github.com/advisories/GHSA-3gxm-wfjx-m847))
Action: Map CVE-2026-42052 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8747-1)