GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
![]()

