← Back to feed
general Security Affairs

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

Security Affairs GitLab

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.

1 IOC
Read the full story Security Affairs →

Related Coverage

general WordPress Click2Shell flaw lets hackers execute PHP on the server BleepingComputer · Sep 21 general Microsoft to retire Microsoft 365 Companion apps in December BleepingComputer · Sep 21 general The API was built for applications. What happens when the user is an AI agent? SC Media · Sep 21