Attackers are actively targeting a recently patched vulnerability in the popular DevSecOps platform GitLab that they can ...
CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files ...
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and ...
The vulnerability impacts self-managed CE and EE instances and provides an unauthenticated path to arbitrary file reads. It’s ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability ...
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” ...
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public ...
A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
GitLab users are being strongly advised to apply patches for a critical-severity vulnerability, identified as CVE-2026-85706, ...
A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results