LIVE · cybersecurity feed
Live wire
vulnerability

Hackers Exploit Maximum Severity Flaw in GitLab

CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0

zeroday.news ·

GitLab has urged users to patch a critical vulnerability, identified as CVE-2026-85706, following reports of active exploitation. The flaw, described as an "improper limitation of a pathname to a restricted directory" or "path traversal," affects all versions of GitLab CE/EE from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

The vulnerability allows an unauthenticated user, under specific conditions, to read arbitrary files from the GitLab server. This is due to improper path confinement and a lack of authentication enforcement within the repository commits API. GitLab released patches for the issue on September 10.

While GitLab itself has not publicly confirmed in-the-wild exploitation, cybersecurity vendor watchtower reported detecting "in-the-wild probes" for the critical bug on September 11. The vendor cautioned that widespread, indiscriminate exploitation is likely imminent, based on patterns observed with previous GitLab vulnerabilities.

Organizations operating public-facing self-hosted GitLab instances are strongly advised to apply the patches immediately or restrict public access to their instances. Watchtower also recommended that administrators review log files for HTTP POST requests to "/api/v4/projects/{id}/repository/commits/" URIs that contain "file.path" parameters, as these could indicate exploitation attempts.

On the same day, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) Catalog. CISA highlighted that path traversal vulnerabilities are frequently targeted by malicious actors and pose significant risks, particularly to federal systems.

Civilian federal agencies are mandated to remediate KEV vulnerabilities, with a deadline of September 15 for this particular flaw. CISA also recommends that private sector organizations consider addressing KEV vulnerabilities as a best practice. The agency further advised following applicable BOD 26-04 guidance for cloud services or discontinuing use of the product if no mitigations are available.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice