# US regulatory and public-data digest — 7 UTC calendar dates ending 2026-09-13

> Generated 2026-09-13. Source event dates are bounded to 2026-09-07 through 2026-09-13 UTC; active weather and forward-looking Form 144 dates are the documented exceptions.
> An empty section may reflect no qualifying indexed rows or stale source coverage. Check [freshness](https://api.ai-analytics.org/api/v1/freshness) before treating absence as proof of no event.

## ⚠ Most-actively exploited vulnerabilities (CISA KEV)

- [CVE-2026-85706](https://api.ai-analytics.org/cve/CVE-2026-85706) — **GitLab Community Edition and Enterprise Edition** · remediate by 2026-09-14
  GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing auth
- [CVE-2026-42018](https://api.ai-analytics.org/cve/CVE-2026-42018) — **JFrog Artifactory** · remediate by 2026-09-25
  JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially expos
- [CVE-2026-42016](https://api.ai-analytics.org/cve/CVE-2026-42016) — **JFrog Artifactory** · remediate by 2026-09-25
  JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
- [CVE-2026-84869](https://api.ai-analytics.org/cve/CVE-2026-84869) — **ConnectWise ScreenConnect** · remediate by 2026-09-14
  ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sess
- [CVE-2026-67277](https://api.ai-analytics.org/cve/CVE-2026-67277) — **MikroTik RouterOS** · remediate by 2026-09-13
  MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

## ⚠ NHTSA park-it / park-outside vehicle recalls

_No park-it recalls in this window._

## 🏛️ Federal court filings (high-signal NOS codes)

_No notable cases filed in this window._

## 🚨 Recent DOJ press releases

_No DOJ releases in this window._

## 🔒 Newly added OFAC sanctions

_No recently dated OFAC entries._

## 💉 FDA Class I recalls (life-threatening)

_No Class I recalls in this window._

## 💰 Largest insider sells (SEC Form 4)


## Citation

> AI Analytics. Cross-vertical regulatory digest. Retrieved 2026-09-13T02:07:18.107Z from https://api.ai-analytics.org/today. Source and reuse terms vary; see https://api.ai-analytics.org/license.

---

*[Full feed](https://api.ai-analytics.org/feed.json) · [Dataset catalog](https://api.ai-analytics.org/datasets/) · [Cross-vertical entity timelines](https://api.ai-analytics.org/entity/) · [Source terms](https://api.ai-analytics.org/license)*