A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
Explore the latest news, real-world incidents, expert analysis, and trends in Gitlab — only on The Hacker News, the leading ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity ...
GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public ...
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” ...
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability ...
The most serious flaw, CVE-2026-85706, carries a CVSS score of 10.0 and affects both Community Edition and Enterprise Edition. GitLab said improper path confinement and missing authentication ...
GitLab Duo CLI, now in public beta, lets developers automate an open-ended objective to a governed agentic flow that runs locally and verifies its own work, so ...