2026-09-14
This monthNew Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
In the past 48 hours, several critical security vulnerabilities affecting key web3 and cloud infrastructure components have been disclosed. These include a path traversal vulnerability in GitLab's Com…
RESEARCH: New Web3 Security Vulnerability Disclosures and CVEs (Last 48 Hours)
Summary
In the past 48 hours, several critical security vulnerabilities affecting key web3 and cloud infrastructure components have been disclosed. These include a path traversal vulnerability in GitLab's Community Edition and Enterprise Edition, improper authentication issues in JFrog Artifactory, an authorization flaw that enables privilege escalation, and missing authentication vulnerabilities in MikroTik RouterOS services. Additionally, ConnectWise ScreenConnect faces improper privilege management risks, while Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) expose potential authentication bypasses.
These developments are significant as they highlight ongoing security challenges within web3 ecosystems, impacting both on-premises infrastructure and cloud-based services. The vulnerabilities underscore the necessity for prompt remediation to prevent exploitation by malicious actors.
Key Developments
- 2026-09-11 — GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability: An unauthenticated user can read arbitrary files due to improper path confinement and missing authentication enforcement in the repository commits API. CISA KEV Catalog
- 2026-09-11 — JFrog Artifactory Improper Authentication Vulnerability: When anonymous access is disabled, an unauthenticated caller could receive an internal anonymous-user token, potentially exposing sensitive resources. CISA KEV Catalog
- 2026-09-11 — JFrog Artifactory Incorrect Authorization Vulnerability: Allows privilege escalation due to a validation check of the token signature/issuer rather than its scope. CISA KEV Catalog
- 2026-09-11 — ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability: May allow attackers to perform file transfers and execute code through active remote sessions without authorization. CISA KEV Catalog
- 2026-09-10 — MikroTik RouterOS Missing Authentication for Critical Function Vulnerability: Allows kernel memory disclosure and denial of service in the btest service due to missing authentication. CISA KEV Catalog
- 2026-09-10 — MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability: Enables privilege escalation by altering the trusted RouterOS policy mask. CISA KEV Catalog
- 2026-09-09 — Cisco Secure Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability: Could allow unauthenticated attackers to bypass authentication and execute scripts for root access. CISA KEV Catalog
- 2026-09-09 — Google Chromium V8 Out of Bounds Write Vulnerability: Enables arbitrary code execution inside the sandbox via a crafted HTML page, affecting multiple browsers including Chrome and Edge. CISA KEV Catalog
Sources
- NVD - Vulnerabilities
- cisa.gov/known-exploited-vulnerabilities-catalog
- CVE: Common Vulnerabilities and Exposures
- GitHub - aquasecurity/trivy: Find vulnerabilities, misconfigurations...
- A Theory of Open Source Security: The Spillover of Security Knowledge in Vulnerability Disclosures Through Software Supply Chains