GitLab issued emergency patches for two critical vulnerabilities, including CVE-2026-85706 with a CVSS score of 10.0 that could let unauthenticated attackers read any file on affected self-managed servers. WatchTowr Labs reported active probing for the flaws, and CISA added both issues to its Known Exploited Vulnerabilities list. #GitLab #CVE-2026-85706 #CVE-2026-87719 #WatchTowrLabs #CISA #KEV
Keypoints
- GitLab released emergency patches for two high-severity vulnerabilities.
- CVE-2026-85706 can allow unauthenticated file read access on affected servers.
- CVE-2026-87719 affects GitLab Enterprise Edition and may expose settings and passwords.
- WatchTowr Labs said attackers are already probing the internet for the path traversal flaw.
- CISA added both vulnerabilities to its Known Exploited Vulnerabilities list.
Read More: https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/