1. Basic Information
Original Title: GitLab urges users to patch max severity path traversal flaw
Source: BleepingComputer, GitLab
Publication Date: 2026-09-11
Severity: Critical
1. Basic Information Original Title: GitLab urges users to patch max severity path...
1. Basic Information
Original Title: GitLab urges users to patch max severity path traversal flaw
Source: BleepingComputer, GitLab
Publication Date: 2026-09-11
Severity: Critical

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked…

GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.

Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public disclosure.

Hackers started exploiting CVE-2026-19478, a critical, unauthenticated GitLab vulnerability, shortly after public disclosure.

GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under…

GitLab CE/EE security updates resolve 13 vulnerabilities, including high-severity code execution and information disclosure bugs.