Critical Vulnerabilities Under Active Attack: What Compliance and Security Teams Must Do Now
September 21, 2026
weekly-compliance-roundup
This Week in Compliance & Cybersecurity: Active Exploitation Warnings Dominate the Threat Landscape
This week’s most pressing news for security and compliance teams centers on a wave of actively exploited critical vulnerabilities flagged by CISA. Organizations relying on ConnectWise ScreenConnect, VMware vCenter, and GitLab need to treat these alerts as immediate action items — not items for the next sprint.
Three Critical Flaws, One Urgent Message: Patch Now
CISA issued warnings on three separate high-severity vulnerabilities this week, all of which are being actively exploited in the wild:
ConnectWise ScreenConnect
A critical-severity flaw in ScreenConnect — a widely used remote access tool — is now being actively targeted by attackers. Remote access tools are a high-value target because they provide direct pathways into corporate infrastructure. If your organization uses ScreenConnect, this is a code-red patching priority.
Business impact: Unpatched remote access tools can expose your entire internal network. For companies undergoing SOC 2 or ISO 27001 audits, failure to apply critical patches in a timely manner is a direct control failure that auditors will flag.
VMware vCenter — Now in Ransomware Gangs’ Crosshairs
The critical VMware vCenter remote code execution (RCE) vulnerability, patched back in July, has now been picked up by ransomware gangs. The window between patch availability and active ransomware exploitation has closed. Organizations that delayed patching are now directly in the line of fire.
Business impact: VMware vCenter is commonly used to manage virtualized infrastructure at scale. A successful RCE exploit here can mean full environment compromise. Ransomware incidents carry significant regulatory reporting obligations under frameworks including HIPAA, PCI DSS, and various state breach notification laws. The cost of non-patching far exceeds the cost of a maintenance window.
GitLab — Maximum Severity Flaw Now Actively Exploited
CISA confirmed that a maximum-severity GitLab vulnerability is now being exploited in real-world attacks. GitLab is central to software development pipelines at thousands of companies, making this a supply chain risk as much as a direct infrastructure risk.
Business impact: Compromised source code repositories can introduce vulnerabilities into your own products, expose customer data embedded in configuration files, and undermine software integrity attestations required under emerging software supply chain regulations. Organizations with SOC 2 Type II commitments around availability and confidentiality should treat this as a high-priority incident response trigger.
What Compliance Teams Should Do This Week
- Verify patch status for ScreenConnect, VMware vCenter, and GitLab across all environments — production, staging, and development.
- Document your response timeline. Auditors will look for evidence that your vulnerability management program identifies and remediates critical findings within defined SLAs.
- Review your vendor inventory. If third-party vendors in your supply chain use any of these tools, assess their patch status as part of your vendor risk management process.
- Check your incident response plan. With ransomware actively exploiting VMware vCenter, now is the time to confirm your IR playbooks are current and tested.
- Update your risk register. These three CVEs should be formally logged with assessed severity and remediation status.
The Bigger Picture: CISA Warnings as Compliance Triggers
When CISA adds a vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, it is not simply an advisory — for federal agencies it carries a binding remediation deadline, and for private sector organizations it serves as a strong signal that the threat is real and active. Building a workflow that monitors CISA KEV additions and triggers your patch management and risk documentation processes is a practical step any compliance program can take to stay ahead.
The pattern this week — three separate critical warnings in the span of three days — reinforces that vulnerability management must be treated as a continuous, operationalized process rather than a quarterly checkbox.
Sources
- Critical ScreenConnect flaw now actively exploited in attacks — BleepingComputer
- CISA: Critical VMware RCE flaw now exploited by ransomware gangs — BleepingComputer
- CISA: Hackers now exploit max severity GitLab flaw in attacks — BleepingComputer