GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825.

Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public disclosure.