24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 18 Posts
  • 20 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-85706 is now in the KEV but the CVE still isn't published. LMAO. Go hack and patch more GitLab shit.

  • 5
  • 6
  • 0
  • 6h ago
Profile picture fallback

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure

Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.

The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.

Affected versions include:

• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2

GitLab disclosed and patched the vulnerability on September 10.

Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.

Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.

GitLab.com is already patched.

Source: docs.gitlab.com/releases/patch

  • 1
  • 2
  • 0
  • 9h ago
Profile picture fallback

@cR0w no mention of exploitation from CNA GitLab

CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE

GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Impacted Versions: GitLab CE/EE: all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)

Thanks s3ntago for reporting this vulnerability through our HackerOne bug bounty program.

docs.gitlab.com/releases/patch

  • 1
  • 1
  • 0
  • 6h ago
Profile picture fallback

🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1

PoC: github.com/guneykabel/cve-2026

  • 0
  • 2
  • 0
  • 9h ago
Profile picture fallback

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 12h ago
Profile picture fallback

📰 GitLab Patches Critical CVSS 10.0 Path Traversal Vulnerability

GitLab releases emergency patches for a critical CVSS 10.0 path traversal flaw (CVE-2026-85706). Unauthenticated attackers can read arbitrary files. Active scanning detected. Upgrade self-managed instances NOW. #GitLab #CVE #CyberSecurity #PatchNow

🔗 cyber.netsecops.io/articles/gi

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

Critical GitLab Vulnerabilities Exposed: Deep Dive into the CVSS 10.0 Path Traversal (CVE-2026-85706) & GraphQL Exploits

GitLab fixes CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal flaw, alongside CVE-2026-87719. Learn affected versions and patch now

thecybersecguru.com/news/gitla

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
  • 0
  • 2
  • 0
  • 3h ago
Profile picture fallback
A critical GitLab path traversal flaw (CVE-2026-85706) is being exploited in the wild, enabling unauthenticated arbitrary file reads; upgrade immediately.
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
GitLab patched CVE-2026-85706, a max-severity path traversal flaw that could expose credentials and sensitive data. watchTowr also reported early probing against exposed GitLab systems. #GitLab #CVE-2026-85706 #watchTowr
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
CVE-2026-85706 enables unauthenticated path traversal in GitLab repository commits API, allowing arbitrary file reads and credential exposure via in-the-wild probes.
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
📢 GitLab corrige une faille critique de path traversal (CVE-2026-85706) dans l'API commits L'article couvre la divulgation et le correctif de deux vulnérabilités critiques affectant la plateforme GitLab. 🔴 Vulnérabilité… 🟢 vérification factuelle haute #GitLab #PathTraversal #Cyberveille
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
GitLab CVE-2026-85706 was exploited within a day of disclosure. The critical path traversal flaw (CVSS 10.0) can let unauthenticated attackers read arbitrary files. #GitLab #CVE202685706 #PathTraversal
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
🚨GitLab releases 19.3.2, 19.2.6, 19.1.8 patch 2 critical CVEs: CVE-2026-85706: A 10.0 arbitrary file read via unauth path traversal in repo commits API, affecting CE and EE versions from 18.7. CVE-2026-87719: A 9.9 insecure deserialization via GraphQL subscription, affecting EE versions from 18.3.
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw in the commits API that is already seeing probes and could expose arbitrary files. CVE-2026-87719 also fixed in GitLab EE. #GitLab #CVE202685706 #CVE202687719
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
GitLab rushed emergency patches for 2 critical flaws. CVE-2026-85706 can let unauthenticated attackers read files, while CVE-2026-87719 may expose settings and passwords. #GitLab #CVE202685706 #CISA
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

04 Mar 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
75.75%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Statistics

  • 7 Posts
  • 2 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Cisco confirma que el fallo CVE-2026-20079 de Secure FMC está siendo explotado en ataques

blog.elhacker.net/2026/09/cisc

  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback

The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.

#Cybersecurity #Geopolitics #TechNews

  • 0
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
#Cisco confirms CVE-2026-20079 #SecureFMC flaw exploited in attacks https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/ #cybersecurity
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Cisco Secure Firewall Management Center FMC Vulnerability Chain Exploitation https://www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316 https://flagthis.com/tldr/7247 ##Cisco ##ZeroDay ##Ransomware ##APT ##Vulnerability
  • 1
  • 0
  • 0
  • 2h ago
Profile picture fallback
Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47682/
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)(Cisco FMCの脆弱性、国家支援型攻撃者やランサムウェア攻撃者が悪用) #HelpNetSecurity (Sep 10) www.helpnetsecurity.com/2026/09/10/c...
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) - Help Net Security www.helpnetsecurity.com/2026/09/10/c...
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

10 Sep 2026
Published
11 Sep 2026
Updated

CVSS v4.0
HIGH (7.2)
EPSS
0.34%

KEV

Description

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls. The security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . Panorama is impacted by this vulnerability.

Statistics

  • 1 Post
  • 61 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Palo-Alto are calling resellers and asking them to call customers to tell them to update their Palo-Alto PA and VM firewalls to cover CVE-2026-0310 - an unauthenticated XML parsing vulneraility which causes a buffer overflow leading to code execution, on the PA (physical) firewalls via the dataplane.
security.paloaltonetworks.com/

HT @databeestje

  • 37
  • 24
  • 0
  • 3h ago

Overview

  • Forgejo
  • Forgejo

10 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.50%

KEV

Description

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

CVSS: 9.9

Foregejo Update/Notes: codeberg.org/forgejo/forgejo/s

  • 2
  • 1
  • 0
  • 5h ago
Profile picture fallback

A critical Forgejo remote code execution flaw, tracked as CVE-2026-89094, threatens Git servers. Patch this Forgejo remote code execution bug today.

securityonline.info/forgejo-re

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Mikrotik
  • RouterOS

05 Sep 2026
Published
11 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.69%

Description

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Statistics

  • 4 Posts
  • 4 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Executive alert: CVE-2026-86060 actively threatens MikroTik RouterOS infrastructure. Review board-ready risk evaluation protocols, network asset integrity measures, and strategic remediation steps to protect your enterprise value today.

thecybermind.co/stnk

  • 0
  • 1
  • 0
  • 15h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added two actively exploited MikroTik RouterOS vulnerabilities to its KEV Catalog. - IOCs: CVE-2026-67277, CVE-2026-86060 - #CVE-2026-67277 #CVE-2026-86060 #ThreatIntel
  • 2
  • 0
  • 0
  • 22h ago
Profile picture fallback
CISA Adds Two Known Exploited Vulnerabilities to Catalog(CISAが既知の悪用された脆弱性2件をカタログに追加) #CISA (Sep 10) CVE-2026-67277 MikroTik RouterOSにおける重要機能の認証欠落の脆弱性 CVE-2026-86060 MikroTik RouterOS コマンドにおける引数区切り文字の不適切な無効化の脆弱性 www.cisa.gov/news-events/...
  • 1
  • 0
  • 0
  • 22h ago
Profile picture fallback
~Cybergcca~ MikroTik RouterOS flaws are exploited in the wild; CISA added two CVEs to KEV, while four other vendors require updates. - IOCs: CVE-2026-67277, CVE-2026-86060, CVE-2026-67276 - #CVE #MikroTik #ThreatIntel
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

29 Jul 2026
Published
11 Sep 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
11.15%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 2 hours ago

Bluesky

Profile picture fallback
Cisco Secure Firewall Management Center FMC Vulnerability Chain Exploitation https://www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316 https://flagthis.com/tldr/7247 ##Cisco ##ZeroDay ##Ransomware ##APT ##Vulnerability
  • 1
  • 0
  • 0
  • 2h ago
Profile picture fallback
Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47682/
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)(Cisco FMCの脆弱性、国家支援型攻撃者やランサムウェア攻撃者が悪用) #HelpNetSecurity (Sep 10) www.helpnetsecurity.com/2026/09/10/c...
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) - Help Net Security www.helpnetsecurity.com/2026/09/10/c...
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.33%

KEV

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 5 Posts

Last activity: 12 hours ago

Bluesky

Profile picture fallback
Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could enable unauthenticated RCE on Security Gateway and Management systems under specific conditions. #CheckPoint #VPNFlaws #RCE
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Check Point Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 URL: community.checkpoint.com/t5/General-T... Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.8
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Check Point released patches for two unauthenticated VPN-related RCE vulnerabilities (CVE-2026-85102, CVE-2026-85103) with mitigations via manual VPN rules.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. www.securityweek.com/check-point-...
  • 0
  • 0
  • 1
  • 12h ago

Overview

  • Progress Software
  • Chef Automate

11 Sep 2026
Published
11 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

KEV

Description

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CRITICAL vuln (CVE-2026-80462) in Progress Chef Automate (4.13.516 – 4.13.519): API gateway auth bypass enables unauth’d privilege escalation. Restrict API access & review logs until patch confirmed. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

Progress patched a critical Chef Automate vulnerability tracked as CVE-2026-80462. Fix this Chef Automate vulnerability to stop DevOps account takeovers.

securityonline.info/chef-autom

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
10 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
5.60%

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
In my latest blog post examining a NetScaler auth bypass CVE-2026-19490, I break down all the different ways the impact can vary depending on the the appliance configuration – ranging from DoS to full root compromise. bishopfox.com/blog/mind-th...
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Citrix NetScaler ADC / Gateway CVE-2026-19490 Vulnerability Checker https://packetstorm.news/files/231210 #exploit
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Gen traced the payload to Alibaba Cloud in Hong Kong. A downloader dropped a malicious DLL and encrypted GRAYRABBIT, providing remote shell access, file transfer and module loading. Tencent fixed CVE-2026-51990, but Sogou still ships Chromium 80. The outdated browser remains a concern. #threatintel
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method. The vulnerability is actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link. www.gendigital.com/blog/insight...
  • 0
  • 0
  • 0
  • 16h ago
Showing 1 to 10 of 72 CVEs