Threat actors began exploiting CVE-2026-85706 in GitLab just one day after public disclosure, taking advantage of a critical path traversal flaw that can let unauthenticated users read arbitrary files. WatchTowr also reported that mass exploitation is likely soon, while GitLab’s latest patches additionally fix CVE-2026-87719 and several other serious vulnerabilities. #GitLab #CVE-2026-85706 #CVE-2026-87719
Keypoints
- Attackers began probing GitLab CVE-2026-85706 within one day of disclosure.
- The flaw is a critical path traversal issue with a CVSS score of 10.0.
- It can allow unauthenticated users to read arbitrary files from GitLab servers.
- WatchTowr warned that mass exploitation is likely to follow soon.
- GitLab’s latest patches also fix CVE-2026-87719 and other high-severity issues.
Read More: https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/