Daily Signal — 2026-09-13
This is FLLC's automated morning scan of named public sources. It is intentionally concise: what changed, why it may matter, what to verify next, and where the claim came from. 5/5 sources were live for this edition.
At a glance
- CVE-2026-84869 leads the latest CISA exploited-vulnerability entries.
- CISA advisory watch: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.
- M5.2 was the strongest M4.5+ event in the USGS 24-hour feed.
- Falcon 9 Block 5 | O3b mPower 11-13 is next on the public launch manifest.
Exploited vulnerabilities
- CVE-2026-84869 — ConnectWise ScreenConnect. Added 2026-09-11; remediation due 2026-09-14. ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-42016 — JFrog Artifactory. Added 2026-09-11; remediation due 2026-09-25. JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-42018 — JFrog Artifactory. Added 2026-09-11; remediation due 2026-09-25. JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV priority queue
- CVE-2026-84869 · ConnectWise ScreenConnect · added 2026-09-11 · due 2026-09-14
- CVE-2026-42016 · JFrog Artifactory · added 2026-09-11 · due 2026-09-25
- CVE-2026-42018 · JFrog Artifactory · added 2026-09-11 · due 2026-09-25
- CVE-2026-85706 · GitLab Community Edition and Enterprise Edition · added 2026-09-11 · due 2026-09-14
- CVE-2026-86060 · MikroTik RouterOS · added 2026-09-10 · due 2026-09-13
- CVE-2026-67277 · MikroTik RouterOS · added 2026-09-10 · due 2026-09-13
- CVE-2026-19490 · Citrix NetScaler · added 2026-09-09 · due 2026-09-12
- CVE-2025-25249 · Fortinet Multiple Products · added 2026-09-09 · due 2026-09-12
Defensive move: match the cited products against your actual inventory, follow the vendor remediation, and prioritize internet-facing or privileged systems. A catalog entry is evidence of exploitation in the wild—not proof that your environment is compromised.
Threat-actor and campaign watch
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — published 2026-09-08 12:00 UTC. This is an actor-linked signal because the official CISA title or summary explicitly names an actor, campaign, or ransomware operation; FLLC is not independently assigning attribution.
Trace responsibly: preserve the source and timestamp, map only explicitly reported infrastructure and MITRE ATT&CK behaviors, separate observed facts from assessment, and record confidence. A vendor, geography, malware family, or IP address alone is not actor attribution.
Earth systems
-
M5.2 — 43 km ESE of Port-Olry, Vanuatu, 2026-09-13 07:19 UTC. The M4.5+ day feed contained 7 events when retrieved. Open the USGS event.
-
NOAA space-weather data was unavailable or malformed during this run.
Interpretation boundary: earthquake magnitude does not establish local impact, and Kp is planetary-scale context. Follow the issuing agency and local authorities for decisions.
Orbital watch
- Falcon 9 Block 5 | O3b mPower 11-13 — SpaceX; Go for Launch; no-earlier-than 2026-09-13 18:49 UTC. Pad: Space Launch Complex 40 · Cape Canaveral SFS, FL, USA.
Launch times and status can move. Confirm with the launch provider before travel, viewing, or operational decisions.
Source health
- CISA: live
- ADVISORIES: live
- USGS: live
- NOAA: live
- LAUNCHES: live
Primary sources
- CISA Known Exploited Vulnerabilities
- CISA Cybersecurity Advisories
- USGS M4.5+ earthquakes, past day
- NOAA SWPC planetary K-index
- Launch Library 2 upcoming manifest
Retrieved 2026-09-13 15:15 UTC. Automated, source-linked, and reviewed by machine rules for completeness. It is not emergency, navigational, investment, or legal advice.