A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability ...
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public ...
A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA ...
GitLab users are being strongly advised to apply patches for a critical-severity vulnerability, identified as CVE-2026-85706, ...
The path traversal flaw, allowing access to arbitrary files, adds to a growing set of input validation issues in AI pipelines. Security researchers are warning that applications using AI frameworks ...