CyberHighConfirmedAccelerating
7.9
CISA warns hackers exploiting max-severity GitLab flaw in active attacks
BleepingComputerLO·US·about 23 hours ago
A maximum-severity path traversal vulnerability (CVE-2026-85706, CVSS 10) affects GitLab CE and EE, enabling potential remote code execution and supply-chain compromise. Exploitation details are not yet public, but the flaw's severity and GitLab's widespread use in CI/CD pipelines elevate risk. Organizations should prioritize patching and monitor for active exploitation.