Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
blog

FOCUS FRIDAY: TPRM Insights on Critical Vulnerabilities in ScreenConnect, Exim, Citrix NetScaler, Apache Tomcat, and Langflow

Published

Sep 25, 2026

Authors

Ferdi Gül

Contributors

Hakan Karabacak

Introduction

This week's Focus Friday® covers five FocusTags® spanning remote support software, mail transfer agents, enterprise perimeter appliances, web application servers, and AI development platforms. Two tags carry actively exploited CISA Known Exploited Vulnerabilities listings with confirmed in-the-wild exploitation: ScreenConnect's critical missing authorization flaw enabling a worm-like propagation campaign documented by Huntress across unrelated organizations, and Citrix NetScaler ADC and Gateway's authentication bypass vulnerability. Langflow continues its streak as the most prolific source of critical AI platform vulnerabilities, disclosing its fourth critical flaw this reporting cycle — a server-side request forgery via an incomplete code security scanner that produces false 'validated: true' signals while executing attacker-controlled code server-side. Apache Tomcat's September release includes eight vulnerabilities, including a WebSocket security constraint bypass and a CLIENT_CERT authentication failure, among others. Exim closes the week with two PROXY protocol memory flaws.

The highest-urgency events this week are ScreenConnect's confirmed worm-like exploitation campaign — in which modified ScreenConnect clients propagate a four-stage malware chain to every newly connected Host session — and Citrix NetScaler's authentication bypass, which targets the perimeter authentication boundary of internet-facing appliances and has a public proof-of-concept available. For TPRM professionals, both are incident-response-class events that require immediate vendor outreach rather than standard patch tracking. Langflow's fourth critical vulnerability in a single reporting cycle raises systemic architecture concerns that extend beyond patch management.

Filtered view of vendors with ScreenConnect - Sep2026 FocusTag® on the Black Kite platform.

Filtered view of vendors with ScreenConnect - Sep2026 FocusTag® on the Black Kite platform.

ScreenConnect - Sep2026

What is this vulnerability?

ConnectWise ScreenConnect is a widely deployed remote support and access platform used by IT teams and Managed Service Providers globally to deliver remote assistance and manage endpoints. CVE-2026-84869 (CVSS 9.9, EPSS 0.38%) is a missing authorization vulnerability (CWE-862, CWE-269) in the ScreenConnect client's file-transfer handling logic. Under certain conditions during active remote support or access sessions, file-transfer actions are processed without proper authorization or Host confirmation, allowing files to be transferred to and executed on the Host client system — including through elevated execution actions. The CVSS scope is Changed, confirming that exploitation impacts resources beyond the vulnerable component itself.

CVE-2026-84869 is not merely a theoretical flaw — it is the technical foundation of an actively exploited worm-like campaign documented by Huntress across multiple unrelated organizations. Threat actors deploy modified ScreenConnect clients that exploit the unauthorized file-transfer execution capability to deliver a four-stage VBScript chain (1.vbs–4.vbs) to every newly connected Host session. The chain profiles the host for security tools and RAM, downloads an AES-encrypted payload map from Dropbox, and deploys one of two branches: state 010 installs a concealed ScreenConnect backdoor via UAC bypass, disables AMSI, adds C:\Users to Defender exclusions, and propagates the VBS chain to all future Host connections — creating self-replicating behavior; state 011 additionally deploys XMRig (renamed SearchIndex.exe) and wstunnel tunneling (renamed Themes.exe). CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on September 11, 2026. ScreenConnect servers are not impacted; only client deployments prior to version 26.6.5 are affected. Cloud-hosted ScreenConnect servers have been automatically patched; on-premises deployments require immediate manual upgrade.

Why should TPRM professionals care?

MSPs running ScreenConnect represent a standing supply chain risk amplifier: a single modified client propagating through an MSP's ScreenConnect environment can reach every endpoint managed across every client organization. The worm-like propagation mechanism means that the scope of compromise expands automatically with each new Host connection to an infected client — no additional attacker action required after initial deployment. For organizations that rely on MSPs or IT support providers using ScreenConnect, this vulnerability is effectively a supply chain exposure: your vendor's infected remote support client becomes your breach. TPRM teams must verify that vendors have upgraded to ScreenConnect 26.6.5 and conducted IoC reviews — patching alone does not address hosts that may have already been compromised prior to the update.

What questions should TPRM professionals ask vendors?

  1. Can you confirm if you have upgraded all instances of ConnectWise ScreenConnect to version 26.6.5 or later to mitigate the risk of CVE-2026-84869?
  2. Have you audited your ScreenConnect server audit logs for RunFiles or RanFiles entries showing execution of 1.vbs, 2.vbs, 3.vbs, 4.vbs, or WindowsServiceHost.vbs from Process: Guest to detect any active exploitation?
  3. Have you reviewed all endpoints managed via ScreenConnect for the presence of indicators of compromise such as WindowsServiceHost User Run Key, files under C:\Users\Public\Libraries\Default\Lib\Lib1, ScreenConnect client ID 7a4d7d66502d4260 with no uninstall registry entry, and connections to homehub.opik[.]net:443, tele-sync.opik[.]net, borertors92.anondns[.]net?
  4. If you were unable to immediately upgrade to ScreenConnect 26.6.5, did you disable the TransferFiles permission across all session roles as a temporary mitigation measure against CVE-2026-84869?

Remediation recommendations

  • Upgrade all ScreenConnect on-premises deployments to version 26.6.5 or later immediately; cloud-hosted customers must reinstall host clients and access agents — server-side auto-update does not update the client-side components affected by this vulnerability.
  • Treat any ScreenConnect deployment that was not patched before CISA's September 11, 2026 KEV listing as potentially hosting a compromised client; conduct audit log review for VBS execution indicators and IoC hunt across all managed endpoints.
  • Reimage confirmed compromised hosts from known-good media; the attack chain's depth — including AMSI bypass, Defender exclusion, concealed backdoor, and cryptocurrency miner — makes in-place remediation unreliable.
  • If immediate upgrade is blocked by a maintenance window, apply the temporary mitigation of disabling TransferFiles permissions across all session roles as a partial exposure reduction measure.
Black Kite's ScreenConnect - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite's ScreenConnect - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Exim Mail - Sep2026

What is this vulnerability?

Exim is one of the most widely deployed open-source Mail Transfer Agents globally, handling SMTP email delivery across enterprise, hosting, ISP, and government environments. Two high-severity vulnerabilities were disclosed by the Exim maintainers on September 18, 2026 in the security release for Exim 4.100.1, both affecting the PROXY protocol handling subsystem — a feature used to preserve original client connection metadata when Exim operates behind a proxy or load balancer. CVE-2026-94054 (CVSS 7.0, CWE-787) is an out-of-bounds write in PROXY Protocol v1 parsing: a remote attacker can trigger a read of approximately 230 bytes past the end of a heap allocation followed by a single NUL-byte write, producing heap corruption. CVE-2026-94056 (CVSS 7.5, CWE-908) is a use of uninitialized resource in PROXY Protocol v2 parsing: a remote attacker can cause uninitialized stack memory to be transmitted, leaking sensitive process data.

Both vulnerabilities carry Attack Complexity: High because exploitation requires the attacker to already control or have compromised the proxy positioned in front of the Exim server — they are not directly reachable from arbitrary internet connections against a default Exim configuration. The PROXY protocol feature (hosts_proxy) is disabled by default, further narrowing the affected population to deployments that have explicitly enabled it. Neither CVE carries a CISA KEV listing or confirmed public exploitation, and no public proof-of-concept has been reported. The Exim security release 4.100.1 also addresses two additional lower-severity issues: a GnuTLS use-after-free (CVE-2026-94055, Low severity) in non-default TLS-on-connect settings, and an SMTP smuggling flaw (CVE-2026-94057, Medium severity) affecting all Exim versions. No workaround is available for CVE-2026-94054 or CVE-2026-94056; upgrade to Exim 4.100.1 is the only remediation. Approximately 1.9 million internet-facing Exim instances were identified across all versions via Shodan.

Why should TPRM professionals care?

Exim's massive install base — spanning hosting providers, ISPs, enterprises, and government environments, with nearly two million internet-facing instances — makes any vulnerability class in Exim broadly relevant for TPRM portfolio assessment. While CVE-2026-94054 and CVE-2026-94056 require proxy compromise as a prerequisite, the SMTP smuggling flaw (CVE-2026-94057) affects all Exim versions regardless of configuration and enables message injection attacks relevant to email security and anti-spoofing controls. The primary TPRM question is version currency: vendors running Exim prior to 4.100.1 are exposed to the full four-vulnerability set, and the widespread hosting-provider bundling of Exim means many vendors may not be aware they are running it or which version is deployed.

What questions should TPRM professionals ask vendors?

  1. Have you upgraded all instances of Exim to version 4.100.1 to mitigate the risk of CVE-2026-94054 and CVE-2026-94056?
  2. Can you confirm if the PROXY protocol feature (hosts_proxy) is disabled in your Exim instances, as it is required for both CVE-2026-94054 and CVE-2026-94056 to be exploited?
  3. Have you implemented measures to harden and monitor any load balancer or reverse proxy sending PROXY protocol headers to Exim, as compromise of these proxies is a precondition for exploitation of CVE-2026-94054 and CVE-2026-94056?
  4. Are you reviewing Exim logs for malformed or unexpected PROXY protocol headers that could indicate attempted exploitation of CVE-2026-94054 and CVE-2026-94056?

Remediation recommendations

  • Upgrade Exim to version 4.100.1 across all deployments immediately; no workaround exists for CVE-2026-94054 or CVE-2026-94056, and all four vulnerabilities in the September 2026 release are remediated only by this version.
  • Disable the PROXY protocol feature (hosts_proxy) on any Exim deployment where it is not operationally required; where required, restrict it strictly to known trusted proxy IP addresses to limit the exploitation prerequisite.
  • Audit all Exim deployments across hosting-provider and control-panel-managed environments to confirm 4.100.1 version currency, as bundled instances may not be updated through standard OS package channels.
Black Kite's Exim Mail - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite's Exim Mail - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Citrix NetScaler - Sep2026

What is this vulnerability?

NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) are widely deployed enterprise perimeter appliances providing application delivery, load balancing, SSL/TLS offloading, and secure remote access. Two vulnerabilities were disclosed by Cloud Software Group in August 2026 and escalated to active exploitation status by September 2026. CVE-2026-19490 (CVSSv4 9.3, CVSSv3 9.8, EPSS 3.37%) is a critical authentication bypass via an alternate path (CWE-288): the SAML HTTP-Redirect binding handler in the packet engine (nsppe) parses SAML assertions with the strict flag disabled and treats the default rejectUnsignedAssertion configuration value as an allow condition, meaning an unauthenticated attacker can submit a SAML response with no signature at all and receive a valid authenticated session. On older builds (14.1-43.55 and earlier, 13.1-61.27 and earlier, and all 13.1 FIPS), exploitation applies to any appliance configured as a Gateway or AAA virtual server regardless of SAML configuration. On more recent builds, a configured SAML action is required — but SAML SSO is an extremely common enterprise deployment pattern. CVE-2026-19489 (CVSSv4 8.8) is a memory overflow (CWE-119) triggered when SIP ALG is enabled in Large Scale NAT configurations, causing unpredictable behavior or denial of service.

CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog on September 9, 2026. A public proof-of-concept and root-cause binary analysis are available on GitHub. The EPSS of 3.37% places this vulnerability in the uppermost tier of exploitation probability across all tracked CVEs globally. NetScaler's historical exploitation record is directly relevant context: CVE-2019-19781 and CVE-2023-3519 were each weaponized at massive scale within days of disclosure by ransomware groups and nation-state actors. No workarounds exist for either CVE; the only remediation is upgrading to NetScaler ADC and Gateway 14.1-73.32 or 13.1-63.21. Cloud Software Group-managed services are not affected.

Why should TPRM professionals care?

NetScaler ADC and Gateway are perimeter-positioned by design — internet-facing and serving as the authentication enforcement point between remote users and internal enterprise applications. Bypassing authentication at this boundary potentially provides access to any internal application or resource protected by the gateway, without requiring any credentials. The combination of a 3.37% EPSS, confirmed active exploitation, public PoC, CISA KEV listing, and NetScaler's documented history of rapid exploitation after disclosure creates an incident-response-class urgency profile. TPRM teams must verify not only that vendors have patched, but also whether the appliance was exposed in a vulnerable configuration before patching and whether a compromise assessment has been performed.

What questions should TPRM professionals ask vendors?

  1. Have you upgraded all customer-managed NetScaler ADC and NetScaler Gateway deployments to version 14.1-73.32 or 13.1-63.21, and for FIPS/NDcPP variants, to 14.1-73.32 FIPS or 13.1-37.277?
  2. Was your NetScaler appliance configured as a Gateway or AAA virtual server with a SAML action configured (or running an older build where SAML is not required) during the period between CVE-2026-19490's disclosure and your patch deployment, and if so, have you conducted a compromise assessment including credential rotation and session termination?
  3. Have you reviewed NetScaler authentication logs for anomalous access patterns, unexpected session creation from external IPs, or successful authentications that do not correspond to known user activity during the vulnerable period?
  4. Have you restricted the NetScaler management interface to trusted internal IP ranges, and evaluated whether WAF policies or IP allowlisting on Gateway virtual server authentication endpoints can serve as defense-in-depth measures?
  5. Given NetScaler's history of rapid exploitation following disclosure of CVE-2019-19781 and CVE-2023-3519, what is your patch deployment SLA for NetScaler emergency advisories, and was this SLA met for CVE-2026-19490?

Remediation recommendations

  • Upgrade all customer-managed NetScaler ADC and NetScaler Gateway deployments to 14.1-73.32 or 13.1-63.21 immediately on an emergency basis outside normal maintenance windows; no workarounds exist and the exploitation risk is immediate.
  • Conduct a compromise assessment for any appliance that ran a vulnerable configuration before patching: rotate all credentials for accounts authenticated through the gateway, terminate all active sessions, and review access logs for unauthorized activity.
  • Inspect the NetScaler configuration for CVE-2026-19490 preconditions using: show authentication samlAction to check for SAML actions, and show vpn vserver / show authentication vserver to confirm Gateway or AAA vserver presence.
Black Kite's Citrix NetScaler - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite's Citrix NetScaler - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Apache Tomcat - Sep2026

What is this vulnerability?

Apache Tomcat is one of the most widely deployed open-source web server and servlet container implementations, running Java-based web applications across enterprise, cloud, and on-premises environments globally. On September 23, 2026, the Apache Software Foundation disclosed eight vulnerabilities across Tomcat versions 11.0, 10.1, and 9.0, remediated in versions 11.0.26, 10.1.60, and 9.0.122 respectively. The two most significant flaws both carry CVSS 9.8 scores. CVE-2026-76183 is an Authentication Bypass by Alternate Name: Tomcat incorrectly parses request paths as WebSocket endpoint templates, allowing any attacker to bypass security constraints configured for WebSocket endpoints — bypassing access controls without any credentials. CVE-2026-86248 is an improper authentication flaw stemming from an incomplete prior fix (CVE-2026-34500): CLIENT_CERT authentication fails to enforce certificate revocation as expected under certain conditions when soft-fail is disabled, allowing authentication to succeed with an invalid or revoked certificate.

The remaining six vulnerabilities span HTTP/2 and AJP protocol handling. CVE-2026-86350 (CVSS 9.1) is an HTTP request smuggling flaw via HPACK trailer injection into recycled pooled requests. CVE-2026-77762 (CVSS 8.1) is a race condition affecting async write timeouts. Four denial-of-service vulnerabilities — CVE-2026-78383 (AJP thread pinning, CVSS 7.5), CVE-2026-77791 (WebSocket busy-wait, CVSS 7.5), CVE-2026-79677 (lost async write timeout, CVSS 7.5), and CVE-2026-87022 (per-message-deflate smuggling, CVSS 7.5) — can each be triggered by unauthenticated remote attackers without special configuration. None of the eight CVEs have confirmed active exploitation or CISA KEV listings as of the disclosure date. Apache's own internal impact ratings for CVE-2026-76183 and CVE-2026-86248 are Moderate and Important respectively — the CVSS 9.8 scores reflect theoretical worst-case impact under specific configurations rather than default deployment risk.

Why should TPRM professionals care?

Apache Tomcat's internet-facing deployment footprint is enormous — it serves as the runtime for a broad range of Java web applications across enterprise environments. CVE-2026-76183's WebSocket security constraint bypass is particularly concerning for applications that rely on Tomcat's built-in security constraint model to enforce authentication on WebSocket endpoints: the bypass requires no credentials and applies to the full affected version range spanning Tomcat 9, 10, and 11. CVE-2026-86248 is relevant for any organization using CLIENT_CERT mutual TLS authentication with OCSP-based revocation checking with soft-fail disabled. The four unauthenticated DoS vectors provide additional attack surface for availability disruption against any internet-accessible Tomcat deployment. TPRM teams should verify upgrade status for all vendors known to run Java web applications on Tomcat.

What questions should TPRM professionals ask vendors?

  1. Have you upgraded Apache Tomcat to version 11.0.26, 10.1.60, or 9.0.122 across all deployments, covering all three supported release branches?
  2. Do any Tomcat deployments use WebSocket endpoints protected by Tomcat security constraints, and if so, have these been verified post-upgrade as correctly enforcing access controls following the CVE-2026-76183 fix?
  3. Do any Tomcat deployments use CLIENT_CERT authentication with OCSP-based revocation checking where soft-fail is disabled, and if so, has the CVE-2026-86248 fix been validated for those configurations?
  4. Are AJP connectors enabled on any internet-accessible Tomcat deployments, and if not required, have they been disabled to eliminate the AJP thread-pinning DoS surface from CVE-2026-78383?
  5. What is your patch deployment SLA for Apache Tomcat security releases, and has the September 23, 2026 release been deployed within that SLA?

Remediation recommendations

  • Upgrade Apache Tomcat to version 11.0.26, 10.1.60, or 9.0.122 for the respective deployed branch; these are the complete fixes for all eight vulnerabilities in this release.
  • Disable AJP connectors on any Tomcat deployments where they are not required, eliminating the unauthenticated DoS surface from CVE-2026-78383.
  • Review WebSocket endpoint security constraint configurations post-upgrade to verify correct enforcement, and review CLIENT_CERT/OCSP configurations for correctness where soft-fail is disabled.
Black Kite's Apache Tomcat - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite's Apache Tomcat - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Langflow - Sep2026

What is this vulnerability?

Langflow is an open-source low-code platform used by developers to build visual AI applications and deploy large language model workflows. CVE-2026-12944 (CVSS 9.6, EPSS 0.25%) is the fourth critical Langflow vulnerability disclosed in this reporting cycle, following CVE-2026-7524, CVE-2026-0770, and CVE-2026-9198. It is a Server-Side Request Forgery vulnerability (CWE-918) rooted in an incomplete DANGEROUS_IMPORTS blocklist in Langflow's code security scanner. The scanner correctly blocks subprocess module imports but fails to block the socket and urllib standard library modules. An authenticated user can submit a component containing socket.connect() or urllib.request.urlopen() calls at module level, which execute server-side during component validation with root privileges (UID=0). The scanner simultaneously returns a false 'validated: true' signal — actively suppressing defensive scrutiny by indicating the submitted code is safe when it is not.

The exploitation chain is particularly damaging in cloud deployments. socket or urllib calls at module evaluation time execute immediately during component validation, before any user-facing confirmation step. In AWS environments, a single request to the IMDSv1 metadata endpoint (http://169.254.169.254/latest/meta-data/iam/security-credentials/) returns full temporary IAM role credentials — enabling complete access to all AWS services permitted to the Langflow service's IAM role, including S3, RDS, Lambda, and any other resources in scope. Lateral movement to PostgreSQL and Redis within the Docker network further extends the blast radius to all data in Langflow's supporting infrastructure. A public proof-of-concept is available on GitHub. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N) with Changed Scope confirms that impact extends beyond the Langflow application boundary to connected cloud and network infrastructure. Affected versions are Langflow OSS 1.0.0 through 1.10.0; fixed in Langflow OSS 1.10.1. Disclosed by IBM.

Why should TPRM professionals care?

Four critical vulnerabilities in a single reporting cycle from the same platform is a systemic architecture signal, not a patch management problem. Langflow's code execution attack surface is fundamental to its design as a visual programming environment — each new critical disclosure reveals a new incomplete defense in the same core validation subsystem. CVE-2026-12944's false 'validated: true' signal is particularly insidious for TPRM: it means that even internal security teams relying on Langflow's own scanner output as a security gate cannot detect the threat. For organizations whose vendors use Langflow as part of their AI development or deployment infrastructure, the question is not only whether they have patched CVE-2026-12944 but whether the platform's security model is appropriate for their production environment and what data sources it has access to.

What questions should TPRM professionals ask vendors?

  1. Have you upgraded Langflow OSS to version 1.10.1 to remediate CVE-2026-12944, and have the three prior critical Langflow CVEs (CVE-2026-7524, CVE-2026-0770, CVE-2026-9198) also been addressed through prior updates?
  2. Is Langflow deployed with internet-accessible interfaces, or is access restricted to internal network users only, given that CVE-2026-12944 requires only authenticated access — the minimum privilege level for any Langflow user?
  3. Does the Langflow deployment have access to cloud provider instance metadata services (AWS IMDSv1, Azure IMDS, GCP metadata server), and if so, have IMDSv2 enforcement or metadata endpoint network-level controls been implemented to limit credential theft via SSRF?
  4. Given that this is Langflow's fourth critical vulnerability in a single reporting cycle, has a broader architectural review been conducted on whether Langflow's deployment scope, data access, and network position are appropriate for the risk profile it presents?
  5. Do you have a process for monitoring Langflow security releases and IBM security advisories for this platform given the high disclosure frequency?

Remediation recommendations

  • Upgrade Langflow OSS to version 1.10.1 immediately; this is the complete fix for CVE-2026-12944 and the fourth critical remediation required in this reporting cycle.
  • Enforce IMDSv2 (instance metadata service v2) on all AWS instances running Langflow to prevent IMDSv1 credential theft via SSRF; restrict Langflow's network access to block connections to cloud metadata endpoints (169.254.169.254) at the network level.
  • Restrict Langflow access to authenticated internal users only and implement network segmentation limiting its access to internal services such as PostgreSQL and Redis to the minimum required for operation.
  • Conduct an architectural review of Langflow's production deployment scope in light of four critical vulnerabilities in a single reporting cycle, evaluating whether its current data access, cloud IAM permissions, and network position are appropriate.
Black Kite's Langflow - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

Black Kite's Langflow - Sep2026 FocusTag® details critical insights on the event for TPRM professionals.

How TPRM Professionals Can Leverage Black Kite for These Vulnerabilities

This week's five FocusTags® span remote support software, mail infrastructure, perimeter security appliances, web application servers, and AI development platforms — demonstrating the breadth of enterprise technology surfaces that TPRM professionals must monitor simultaneously. Black Kite's platform automatically identifies vendors in your third-party portfolio running any of these affected technologies at vulnerable versions, surfacing FocusTag® alerts directly on vendor scorecards without requiring manual research or vendor self-disclosure.

For the two CISA KEV-listed tags — ScreenConnect and Citrix NetScaler — Black Kite enables immediate portfolio-wide identification of which vendors operate affected deployments, allowing TPRM teams to generate prioritized outreach lists and begin structured vendor engagement within hours of the FocusTag® activation. The pre-built vendor questions provided in each tag allow teams to move directly from identification to structured assessment without building custom questionnaires.

For Langflow specifically, Black Kite's FocusTag® history provides a unique TPRM signal: vendors tagged for all four of this reporting cycle's Langflow critical vulnerabilities (CVE-2026-7524, CVE-2026-0770, CVE-2026-9198, CVE-2026-12944) demonstrate a pattern of persistent exposure to a platform with systemic architecture vulnerabilities. The Bridge connector enables automated questionnaire dispatch at scale, allowing TPRM teams to engage all five FocusTag® vendor populations simultaneously without proportionally increasing assessment workload.

Strengthening TPRM Outcomes with Black Kite's FocusTags®

This week's five-tag release illustrates how Black Kite's FocusTags® translate heterogeneous threat intelligence — from worm-like exploitation campaigns to systemic platform architecture vulnerabilities — into structured, actionable TPRM intelligence.

  • Worm-Campaign Supply Chain Visibility: ScreenConnect's actively exploited worm-like campaign creates supply chain risk for every organization whose MSP or IT support vendor runs an infected ScreenConnect client. FocusTags® identify these vendors in your portfolio immediately, enabling vendor outreach before the campaign propagates to your environment through a managed service relationship.
  • Perimeter Authentication Bypass Detection: Citrix NetScaler's CVE-2026-19490 — with a 3.37% EPSS, CISA KEV listing, and public PoC — targets the authentication boundary of internet-facing perimeter appliances. FocusTags® surface vendors running vulnerable NetScaler builds at internet-facing positions, where the authentication bypass directly exposes internal resources to unauthenticated attackers.
  • Systemic Platform Risk Identification: Langflow's fourth critical vulnerability in a single reporting cycle represents a systemic architecture risk rather than a one-time patch event. Black Kite's FocusTag® history enables TPRM teams to identify vendors tagged across multiple Langflow CVEs — a pattern signaling persistent platform exposure that warrants architectural-level vendor engagement beyond individual patch verification.
  • False Positive Vulnerability Scanner Blind Spots: CVE-2026-12944's false 'validated: true' signal means Langflow's own scanner actively reports affected components as safe. Black Kite's external intelligence approach, based on internet-observable signals and version detection rather than platform self-reporting, surfaces this risk regardless of what the vendor's internal scanner reports.
  • Large-Install-Base Rapid Assessment: Exim's approximately 1.9 million internet-facing instances and Apache Tomcat's enormous Java web application deployment footprint represent large vendor populations. FocusTags® enable TPRM teams to prioritize which vendors in these large populations are running the specific vulnerable versions, focusing engagement resources on confirmed-exposed vendors rather than the entire product install base.
  • Automated Multi-Tag Portfolio Scoring: All five FocusTags® automatically update vendor risk scores across the Black Kite platform for third parties with internet-accessible instances of ScreenConnect, Exim, NetScaler, Apache Tomcat, and Langflow at affected versions — providing portfolio-wide risk signal updates simultaneously without manual assessment effort.
  • The Bridge: Scalable Vendor Engagement: With five simultaneous FocusTag® activations, The Bridge connector enables automated questionnaire dispatch to all affected vendor populations at once, converting five parallel vendor engagement workstreams into a single managed workflow and ensuring no affected vendor is missed in the assessment process.

About Focus Friday

Every week, we delve into the realms of critical vulnerabilities and their implications from a Third-Party Risk Management (TPRM) perspective. This series is dedicated to shedding light on pressing cybersecurity threats, offering in-depth analyses, and providing actionable insights.

  • ScreenConnect - Sep2026: CVE-2026-84869, Missing Authorization Vulnerability in ConnectWise ScreenConnect Client File-Transfer Handling Enabling Worm-Like Malware Propagation to Every Connected Host Session.
  • Exim Mail - Sep2026: CVE-2026-94054, CVE-2026-94056, Out-of-Bounds Write and Use of Uninitialized Resource in Exim PROXY Protocol v1 and v2 Handling Enabling Heap Corruption and Stack Memory Disclosure.
  • Citrix NetScaler - Sep2026: CVE-2026-19490, CVE-2026-19489, Critical Authentication Bypass via Unsigned SAML Assertion Acceptance in NetScaler ADC and Gateway and Memory Overflow via SIP ALG.
  • Apache Tomcat - Sep2026: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, and 5 additional CVEs, WebSocket Security Constraint Bypass, CLIENT_CERT Authentication Failure, and HTTP Request Smuggling in Apache Tomcat 9, 10, and 11.
  • Langflow - Sep2026: CVE-2026-12944, CVE-2026-7524, CVE-2026-0770, CVE-2026-9198, Fourth Critical Vulnerability in Langflow OSS This Reporting Cycle — SSRF via Incomplete DANGEROUS_IMPORTS Blocklist Enabling AWS Credential Theft with False 'Validated: True' Signal.
  • N-central - Sep2026: CVE-2026-86218, CVE-2026-86206, CVE-2026-86207, CVE-2026-18556, CVE-2026-18577, Pre-Authenticated CVSS 10.0 Remote Code Execution Zero-Day and Dual Authentication Bypass Vulnerabilities in N-able N-central RMM Platform.
  • Adobe Commerce & Magento: CVE-2026-75650, CVE-2026-7565, Unauthenticated Template Injection Remote Code Execution in Adobe Commerce and Magento Open Source Affecting All Versions.
  • MikroTrick: CVE-2026-67276, CVE-2026-86060, CVE-2026-67277, CVE-2026-67281, CVE-2026-67279, CVE-2026-67278, Six-Vulnerability Set Enabling Unauthenticated RouterOS Takeover via SSH Auth Bypass and Privilege Escalation Chain in MikroTik RouterOS.
  • Fortinet - Sep2026 [Suspected]: CVE-2026-84393, CVE-2026-84391, CVE-2026-22575, Improper Certificate Validation in Agentless ZTNA Portal and Authenticated Denial of Service and Workflow Bypass in FortiOS, FortiProxy, FortiAnalyzer, and FortiManager.
  • MSSQL - Sep2026: CVE-2026-47297, CVE-2026-65669, CVE-2026-67378, CVE-2026-67379, CVE-2026-67636, and 56 additional CVEs, Largest Single-Month SQL Server Disclosure Batch with Unauthenticated RCE and Scope-Breaking Critical Vulnerabilities.
  • SharePoint - Sep2026: CVE-2026-69464, CVE-2026-69716, CVE-2026-69268, and 13 additional CVEs, Six Independent Remote Code Execution Pathways via Low-Privilege Authentication in Microsoft SharePoint Server Subscription Edition.
  • Exchange Server - Sep2026: CVE-2026-69356, CVE-2026-69641, CVE-2026-69355, CVE-2026-55007, and 5 additional CVEs, Unauthenticated XSS Spoofing and Multiple RCE Vulnerabilities in Microsoft Exchange Server.
  • MongoDB - Sep2026: CVE-2026-82067, CVE-2026-82075, CVE-2026-82064, and 18 additional CVEs, Silent Authorization Bypass and Unauthenticated Denial of Service Vulnerabilities in MongoDB Server 7.0, 8.0, and 8.3.
  • Roundcube - Sep2026: No CVE (12 fixes), Zero-Click Stored XSS in TNEF Attachment Handling, SSRF Bypass in CSS Proxy, Email Header Injection, and Cross-User Address Book Access in Roundcube Webmail.
  • Jenkins - Sep2026: CVE-2026-84645, CVE-2026-84647, CVE-2026-84649, CVE-2026-84652, CVE-2026-53435, CVE-2026-70426, Authenticated Remote Code Execution via Deserialization Chain and Multiple Privilege Escalation Paths in Jenkins CI/CD Controller.
  • PaperCut MF/NG - Aug2026: CVE-2026-81578, CVE-2026-82078, Unauthenticated Authentication Bypass via Apache Tapestry Dual-Page Request Format Enabling Unsafe Class Loading Remote Code Execution in PaperCut MF and NG.
  • SonicWall SMA1000 - Aug2026: CVE-2026-83548, CVE-2026-83549, Pre-Authentication SSRF and OS Command Injection Zero-Day Chain Enabling Unauthenticated Remote Code Execution on SonicWall SMA1000 Secure Access Gateways.
  • Sangoma Switchvox: CVE-2026-9586, Unauthenticated SQL Injection via /pa Endpoint Enabling PostgreSQL Superuser OS Command Execution in Sangoma Switchvox SMB Edition.
  • MongoDB BI Connector: CVE-2026-75159, CVE-2026-75573, Kerberos-Triggered Denial of Service and TLS Private-Key Password Disclosure in MongoDB Connector for BI (mongosqld).
  • TrueConf - Aug2026: CVE-2026-72529, CVE-2026-72530, Unauthenticated Pre-Authentication Remote Code Execution via Chained Missing Authentication and Sandbox Escape Vulnerabilities in TrueConf Server, Actively Exploited by Head Mare APT.
  • OpenSSL - Aug2026: CVE-2026-18798, CVE-2026-63072, CVE-2026-63076, and 6 additional CVEs, Denial-of-Service and AEAD Authentication Tag Bypass Vulnerabilities in QUIC, CMS, CMP, DTLS, RPK, and AEAD Components of OpenSSL.
  • Apache Tomcat - Aug2026 (Latest): CVE-2026-65182, CVE-2026-68525, CVE-2026-68569, CVE-2026-65637, and 7 additional CVEs, Multiple Authentication and Authorization Bypass Vulnerabilities in Apache Tomcat Affecting 187,461 Exposed Internet-Facing Services.
  • PostgreSQL - Aug2026: CVE-2026-14669, Heap-Based Buffer Overflow in to_char (timestamptz) Enabling Authenticated Remote Code Execution as OS User in PostgreSQL.
  • WordPress Elementor - Aug2026: CVE-2026-32475, Unauthenticated Arbitrary File Upload to Remote Code Execution via Loop Desynchronization in Elementor Pro WordPress Plugin.
  • Citrix NetScaler - Aug2026: CVE-2026-8452, Pre-Authentication Memory Overflow in SAML Signature Canonicalization enabling Remote Code Execution as Root in NetScaler ADC and NetScaler Gateway.
  • VMware vCenter - Aug2026: CVE-2026-59309, CVE-2026-59310, Authentication Bypass in VMware Directory Service and Directory Traversal RCE in vCenter Syslog Server enabling Unauthenticated Full vCenter Takeover.
  • Zimbra - Aug2026: CVE-2026-73570, Unauthenticated SNMP Command Injection enabling Arbitrary OS Command Execution as zimbra User in Zimbra Collaboration Suite.
  • Oracle WebLogic - Aug2026: CVE-2026-60702, and 7 additional CVEs (CVSS up to 9.9), Multiple Unauthenticated Remote Code Execution and Takeover Vulnerabilities via T3 and IIOP in Oracle WebLogic Server.
  • Roundcube - Aug2026: No CVE, Remote Code Execution via markasjunk Plugin cmd_learn Driver and Server-Side Request Forgery Bypass Vulnerabilities in Roundcube Webmail.
  • Water Sector Campaign: CVE-2017-16740, Active Cyber Campaign Targeting Internet-Facing Rockwell MicroLogix PLCs Causing Operational Disruptions at U.S. Water and Wastewater Utilities.

See Black Kite's full CVE Database and the critical TPRM vulnerabilities that have an applied  FocusTags® at https://blackkite.com/cve-database.

References

https://www.cve.org/CVERecord?id=CVE-2026-84869

https://www.connectwise.com/company/trust/advisories

https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin

https://www.huntress.com/blog/rogue-screenconnect-installations-across-unrelated-hosts-suggest-worm-like-activity

https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog

https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869

https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html

https://www.cve.org/CVERecord?id=CVE-2026-94054

https://www.cve.org/CVERecord?id=CVE-2026-94056

https://nvd.nist.gov/vuln/detail/CVE-2026-94054

https://nvd.nist.gov/vuln/detail/CVE-2026-94056

https://securityonline.info/exim-4-100-1-vulnerabilities/

https://www.cve.org/CVERecord?id=CVE-2026-19490

https://www.cve.org/CVERecord?id=CVE-2026-19489

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939

https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

https://github.com/TarPeg007/CVE-2026-19490

https://tomcat.apache.org/security-11.html

https://tomcat.apache.org/security-10.html

https://tomcat.apache.org/security-9.html

https://nvd.nist.gov/vuln/detail/CVE-2026-76183

https://nvd.nist.gov/vuln/detail/CVE-2026-86248

https://nvd.nist.gov/vuln/detail/CVE-2026-86350

https://gbhackers.com/apache-tomcat-11-0-26-fixes-12-security-flaws/

https://www.cve.org/CVERecord?id=CVE-2026-12944

https://www.ibm.com/support/pages/node/7273426

https://github.com/cflowsec/CVE-2026-12944