π΄ GitLab CVE-2026-85706 β active exploitation
Critical CVSS 10.0 path traversal can expose CI/CD secrets, deploy tokens, SSH keys and cloud credentials. Internet scanning began just one day after the patch.

π΄ GitLab CVE-2026-85706 β active exploitation
Critical CVSS 10.0 path traversal can expose CI/CD secrets, deploy tokens, SSH keys and cloud credentials. Internet scanning began just one day after the patch.
π΄ GitLab CVE-2026-85706
Critical CVSS 10.0 path traversal allows unauthenticated arbitrary file reads. CISA KEV lists the flaw as exploited.
Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.
π΄ GitLab CVE-2026-85706 β CVSS 10.0
Critical unauthenticated path traversal can expose arbitrary files and sensitive secrets on vulnerable GitLab servers. Internet scanning started almost immediately after disclosure.
GitLab rushed emergency patches for 2 critical flaws. CVE-2026-85706 can let unauthenticated attackers read files, while CVE-2026-87719 may expose settings and passwords. #GitLab #CVE202685706 #CISA
GitLab CVE-2026-85706 was exploited within a day of disclosure. The critical path traversal flaw (CVSS 10.0) can let unauthenticated attackers read arbitrary files. #GitLab #CVE202685706 #PathTraversal
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw in the commits API that is already seeing probes and could expose arbitrary files. CVE-2026-87719 also fixed in GitLab EE. #GitLab #CVE202685706 #CVE202687719
GitLab patched critical GitLab vulnerabilities, led by CVE-2026-85706 with a CVSS 10.0 score. Update your server now to protect source code from exposure.
#GitLab #CVE202685706 #Vulnerabilities #DevSecOps #Cybersecurity
securityonline.info/gitlab-vulne...