Description
Statistics
- 18 Posts
- 20 Interactions
Fediverse
CVE-2026-85706 is now in the KEV but the CVE still isn't published. LMAO. Go hack and patch more GitLab shit.
🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
⠀
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2
⠀
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
⠀
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
@cR0w no mention of exploitation from CNA GitLab
CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE
GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability
GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow
⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without…
🤖 AI generated summary
Critical GitLab Vulnerabilities Exposed: Deep Dive into the CVSS 10.0 Path Traversal (CVE-2026-85706) & GraphQL Exploits
GitLab fixes CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal flaw, alongside CVE-2026-87719. Learn affected versions and patch nowhttps://thecybersecguru.com/news/gitlab-cve-2026-85706-cvss-10-path-traversal/
Bluesky
Overview
Description
Statistics
- 7 Posts
- 2 Interactions
Fediverse
Cisco confirma que el fallo CVE-2026-20079 de Secure FMC está siendo explotado en ataques
https://blog.elhacker.net/2026/09/cisco-confirma-que-el-fallo-cve-2026.html
The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.
Bluesky
Overview
- Palo Alto Networks
- Cloud NGFW
Description
Statistics
- 1 Post
- 61 Interactions
Fediverse
Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
https://security.paloaltonetworks.com/CVE-2026-0310
HT @databeestje
Overview
- Forgejo
- Forgejo
Description
Statistics
- 2 Posts
- 3 Interactions
Fediverse
🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
A critical Forgejo remote code execution flaw, tracked as CVE-2026-89094, threatens Git servers. Patch this Forgejo remote code execution bug today.
#Forgejo #RemoteCodeExecution #CVE202689094 #Cybersecurity #DevSecOps
Overview
Description
Statistics
- 4 Posts
- 4 Interactions
Fediverse
Bluesky
Overview
Description
Statistics
- 4 Posts
- 1 Interaction
Bluesky
Overview
- checkpoint
- Quantum Security Gateway
Description
Statistics
- 5 Posts
Bluesky
Overview
- Progress Software
- Chef Automate
Description
Statistics
- 2 Posts
Fediverse
CRITICAL vuln (CVE-2026-80462) in Progress Chef Automate (4.13.516 – 4.13.519): API gateway auth bypass enables unauth’d privilege escalation. Restrict API access & review logs until patch confirmed. https://radar.offseq.com/threat/cve-2026-80462-cwe-306-missing-authentication-for-critical-function-in-progress-software-chef-automate-cfce7409b20e5b5f #OffSeq #ChefAutomate #vuln #CVE202680462
Progress patched a critical Chef Automate vulnerability tracked as CVE-2026-80462. Fix this Chef Automate vulnerability to stop DevOps account takeovers.
#ChefAutomate #CVE202680462 #DevOpsSecurity #Cybersecurity #InfoSec
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts