logo

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

ID: c7b82f16-e528-5df4-bd01-0216f5154758

STIX ID: report--c7b82f16-e528-5df4-bd01-0216f5154758

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

Author: [email protected] (The Hacker News)

...
...

GitLab released emergency patches for multiple critical flaws, including CVE-2026-85706 (path traversal, CVSS 10.0) that can allow unauthenticated arbitrary file reads and has been observed in-the-wild since hours after disclosure, and CVE-2026-87719 (insecure deserialization, CVSS 9.9) affecting self-managed instances; organizations are urged to patch immediately or block public access and to review logs for HTTP POSTs to '/api/v4/projects/{id}/repository/commits/' containing 'file.Path' to detect exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.