GitLab Users Urged to Patch Critical Path Traversal Vulnerability (CVE-2026-85706) Under Active Exploitation
GitLab users are strongly advised to apply patches for a critical-severity path traversal vulnerability, identified as CVE-2026-85706, which is reportedly being exploited in the wild. This flaw allows unauthenticated users to read arbitrary files from the GitLab server under specific conditions. GitLab fixed the vulnerability on September 10, and CISA has added it to its Known Exploited Vulnerabilities catalog, recommending immediate remediation for public-facing self-hosted instances.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai