Cybersecurity · September 12, 2026
GitLab has shipped patches for a maximum-severity flaw, CVE-2026-85706, a path traversal bug in the repository commits API that lets an unauthenticated attacker read arbitrary files from a vulnerable server. Scanning activity targeting the bug appeared within hours of the advisory going public, underscoring how fast attackers move once a CVSS 10.0 issue is disclosed. Admins running self-managed GitLab instances should apply the update without delay.
// source: thehackernews.com ↗