GitLab’s critical flaw is already drawing internet-wide probes
ID: d66a24c2-cc41-5039-abed-87fe6627b402
STIX ID: report--d66a24c2-cc41-5039-abed-87fe6627b402
Feed Name: CyberScoop
Threat Score
GitLab released emergency patches for two critical vulnerabilities—CVE-2026-85706 (unauthenticated path traversal allowing arbitrary file reads, CVSS 10.0) and CVE-2026-87719 (exposure of Advanced Search settings/passwords to certain logged-in users, CVSS 9.9). WatchTowr Labs reported internet-wide probes targeting the path traversal, and CISA added the issues to its Known Exploited Vulnerabilities list; self-hosted, internet-reachable GitLab instances should patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
