Do You Use GitLab, MongoDB, Adobe, MikroTik, or Check Point VPN Products? CERT-In Has Just Flagged Multiple Security Vulnerabilities

India’s cyber agency has issued five fresh vulnerability notes covering widely used developer, database, creative, networking, and VPN products. CERT-In published the alerts on September 16, 2026, with critical ratings for GitLab, Adobe, MikroTik RouterOS and Check Point VPN products, while the MongoDB note carries a medium severity rating.

The alerts are relevant to companies running self-managed GitLab, MongoDB servers and drivers, Adobe applications, MikroTik routers, or Check Point gateways. Two details make the update more urgent: CERT-In says a GitLab flaw is being actively exploited, while Adobe has confirmed exploitation of a critical Commerce and Magento vulnerability.

What Exactly Did CERT-In Flag On September 16?

CERT-In’s latest vulnerability-note list shows five consecutive alerts, CIVN-2026-0456 through CIVN-2026-0460, for MongoDB, GitLab, Adobe, Check Point VPN, and MikroTik RouterOS. The risks range from denial-of-service and information exposure to authentication bypass and remote code execution.

GitLab’s warning stands out because CVE-2026-85706 is already being exploited. GitLab describes it as a critical path-traversal issue affecting self-managed CE and EE installations. Under certain conditions, an unauthenticated attacker could read arbitrary files from the server. The company’s GitLab 19.3.2 security release also provides fixes through versions 19.3.2, 19.2.6 and 19.1.8.

GitLab also says CVE-2026-85706 has been added to CISA’s Known Exploited Vulnerabilities catalogue. That gives defenders another reason to treat exposed self-managed instances as an immediate patching priority rather than waiting for a routine maintenance window.

Adobe’s September security batch is also broad. CERT-In lists Experience Manager, ColdFusion, Photoshop, Illustrator, Animate, Photoshop Mobile, Commerce, Magento Open Source, Acrobat, Acrobat Reader and Campaign Classic. Its Adobe vulnerability note says CVE-2026-75650 affecting Commerce, Commerce B2B, and Magento Open Source is being exploited in the wild.

Which GitLab, MongoDB, Adobe, MikroTik, and Check Point Versions Are Affected?

For GitLab, CERT-In lists 19.3.x before 19.3.2, 19.2.x before 19.2.6, and versions from 10.1.0 to before 19.1.8. The flaws could enable code execution, information theft, security bypass, or service disruption.

The MongoDB security alert from CERT-In covers Server 8.3 before 8.3.9, 8.0 before 8.0.30, and 7.0 before 7.0.41, plus several Java, PHP, C# and C drivers. CERT-In says exploitation could lead to arbitrary code execution, privilege escalation, memory corruption, unauthorized access or data manipulation. Although rated medium, its risk assessment describes a high risk of system compromise.

MikroTik RouterOS has three highlighted CVEs. Depending on the version, attackers may crash a router, escalate privileges through SSH or bypass RSA public-key authentication. CERT-In lists affected branches including RouterOS 7.24 before 7.24.2, 7.x before 7.23.4, and 6.x before 6.49.21. The agency directs users to MikroTik’s September 2026 security update.

Check Point’s alert covers Security Gateway, Security Management Server, and Spark Firewall products across several supported and end-of-support releases. R82.20 is listed as not affected. Crafted VPN certificate data could allow an unauthenticated attacker to execute code and potentially compromise a gateway or management server.

Check Point’s two listed issues are CVE-2026-85102 and CVE-2026-85103. CERT-In says both stem from VPN certificate handling, including improper certificate validation and a heap-based buffer overflow. Because exploitation can occur before authentication, administrators should not treat VPN exposure as protected simply because users normally need credentials to connect.

What Should Users And IT Teams Do Now?

The first job is to identify exposed systems and compare installed versions with the vendor-supported fixed releases. Internet-facing GitLab, VPN, and router infrastructure deserves fast attention because attackers can reach those services remotely.

Key actions include:

  • Patch self-managed GitLab to a fixed release and review logs for signs tied to CVE-2026-85706.
  • Apply MongoDB security updates across servers, libraries, and drivers, not only the database engine.
  • Install Adobe’s September security updates, especially on Commerce and Magento servers exposed online.
  • Upgrade MikroTik RouterOS and restrict management, SSH, and bandwidth-test services to trusted networks where possible.
  • Apply Check Point’s vendor security guidance and review unsupported releases that no longer receive normal fixes.

Do not assume automatic updates cover every product. Adobe enterprise tools, database drivers, routers, and security gateways often follow separate maintenance paths. Keep an asset list, confirm versions after patching, and watch vendor notices for revised guidance.

FAQs

Is every GitLab installation affected by the CERT-In warning?
No, GitLab.com is patched; the alert mainly targets vulnerable self-managed CE and EE installations today.

Why is the Adobe vulnerability alert especially urgent?
Adobe confirmed active exploitation of CVE-2026-75650 affecting Commerce, Commerce B2B and Magento Open Source servers.

Does the MongoDB alert only affect MongoDB Server?
No, CERT-In also lists Java, PHP, C#, C and reactive-streams components among affected MongoDB products.

What can the MikroTik flaws allow attackers to do?
They may crash routers, escalate privileges, bypass SSH authentication, and gain administrative control remotely today.

Is Check Point R82.20 affected by this CERT-In alert?
No, CERT-In specifically lists R82.20 as unaffected while several supported and unsupported releases remain vulnerable.

Explore India’s Biggest Tech Shifts

Could UPI Payments Soon Carry Fees?
Check out the latest debate around charges on merchant UPI payments.

What Must Gaganyaan Still Complete?
Find the crucial testing phases before Indian astronauts can fly.

How Is AI Changing Engineering Careers?
Uncover the skills Indian engineers may need as technology evolves.

What Will India-Russia AI Hub Do?
Explore the new AI centre and its planned technology initiatives.

Can Employees Face Action Over AI?
Look into the risks of entering sensitive taxpayer data into public AI tools.

Related Articles