LIVE · cybersecurity feed
Live wire
CVE-2026-85706critical

Critical GitLab Vulnerability Exploited in Internet-Wide Probes

GitLab has released emergency patches for two high-severity vulnerabilities, including one with a critical CVSS score of 10.0 that allows unauthenticated attackers to read any file on a server. A second vulnerability, rated 9.9, enables authenticated users to potentially access sensitive settings and passwords. Security researchers have already observed internet-wide probes targeting the critical file-reading flaw, urging self-managed GitLab users to update immediately.

zeroday.news ·

GitLab has released emergency patches for two high-severity vulnerabilities in its software development platform, one of which carries the maximum possible severity score and is already being actively probed by attackers across the internet. The company urged operators of self-managed installations to upgrade immediately, while confirming its own hosted service and single-tenant Dedicated offering customers are not impacted.

The more critical of the two flaws, identified as CVE-2026-85706, affects the interface responsible for handling repository commits. This vulnerability, rated with a CVSS score of 10.0, allows an unauthenticated attacker to read any file on the server. The issue stems from improper file path confinement and a lack of authentication enforcement, meaning an attacker does not require an account or credentials to exploit it. This flaw impacts all GitLab releases from version 18.7 up to 19.1.8, as well as the 19.2 and 19.3 lines prior to the recent patches.

A security firm, WatchTowr Labs, reported on Friday that it had already observed internet-wide probes targeting this path traversal vulnerability. The firm stated that the exploit can be triggered with a single HTTP request. Organizations running self-hosted GitLab servers accessible from the open internet are at the highest risk. Defenders are advised to examine their logs for POST requests directed to paths under `/api/v4/projects/{id}/repository/commits/` that include a `file.path` parameter. The firm also cautioned that broad, untargeted exploitation often follows swiftly after a patch is released for GitLab vulnerabilities.

The second vulnerability, CVE-2026-87719, is rated with a CVSS score of 9.9 and exclusively affects GitLab's Enterprise Edition. This flaw enables a logged-in user with Duo Chat access to embed a command within a standard request. This command would then prompt the server to retrieve its own settings for the Advanced Search feature, consequently exposing sensitive information such as settings and passwords. This vulnerability affects Enterprise Edition releases from version 18.3 onwards.

GitLab has provided more detailed information regarding these vulnerabilities on its official website. The Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) list on Friday afternoon, further emphasizing the immediate threat they pose.

vulnerabilities in this storyCVE-2026-85706CVE-2026-87719
gitlabvulnerabilitypatchcvecyberattack
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s