Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove

Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported. Threat actors could exploit it “under certain conditions” and read arbitrary files (credentials, secrets, and other sensitive data) on vulnerable GitLab servers. The company has fixed the vulnerability, which impacts GitLab Community Edition (CE) and Enterprise Edition (EE), and has advised customers with public-facing self-hosted GitLab instances to patch their servers immediately, or remove public access.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

·Dark Reading
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3. 1 score of 10. 0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U. S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

·Rapid7 Blog
Read →
Vulnerabilities & Patches
Emerging1 src

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data. By September 11, active probing and exploitation attempts were already underway. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog. watchTowr researchers are already seeing in-the-wild probes targeting CVE-2026-85706.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

NVD-CVE-2026-85706 - nvd.nist.gov

NVD-CVE-2026-85706 nvd. nist. gov

·NVD
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversa l vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being actively exploited. The vulnerability affects both GitLab Community Edition (CE) and Enterprise Edition (EE). CVE-2026-85706 allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server. The issue stems from improper path confinement and missing authentication enforcement in the repository commits API, allowing attacker-controlled path values to escape the intended repository directory. CISA Warns of Critical GitLab Path Traversal Flaw The flaw is categorized as CWE-35, a path traversal weakness that occurs when an application fails to properly restrict file-path operations to an expected directory.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw. The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0. CVE-2026-85706 is a path traversal vulnerability in GitLab’s repository commits API. GitLab said that, under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication enforcement to read arbitrary files from an affected GitLab server. Path traversal flaws occur when an application fails to properly restrict file paths supplied through requests.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

GitLab security advisory (AV26-917)

Serial Number: AV26-917 Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: • GitLab • Prior to 19.1.8 • Prior to 19.2.6 • Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 • GitLab Docs • GitLab release notes • GitLab Docs • CISA KEV: CVE-2026-85706 GitLab security advisory (AV26-917) - Canadian Centre for Cyber Security

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

GitLab’s critical flaw is already drawing internet-wide probes

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws. The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted. The more serious of the two flaws, tracked as CVE-2026-85706 , sits in the interface that handles repository commits. GitLab said that under certain conditions an attacker could read any file on the server, because the code failed to confine file paths properly and did not enforce authentication.

·CyberScoop
Read →
Vulnerabilities & Patches
Emerging1 src

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

[CISA] CVE-2026-85706 - Confirmed Exploitation

CVE-2026-85706 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-11 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-11 Asserted: 2026-09-11

·CISA KEV
Read →

You've reached the end of current stories for this search.