Perfect-10 GitLab bug under attack days after patch lands
GitLab said the flaw could expose files and credentials, and watchTowr reported in-the-wild probes before CISA added it to its exploited catalog.
7 Articles
7 Articles
Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
A vulnerability with the maximum gravity score is putting under pressure thousands of GitLab installations around the world, and attackers have not wasted time. The critical vulnerability GitLab identified as CVE-2026-85706 is already under active attack, just days after the company released the corrective patch. To confirm it is the Cybersecurity and [...]
A GitLab vulnerability with maximum score already records active exploitation, while exposed facility managers face a race against time to apply patches.
INCIBE-CERT Alerts a Critical Vulnerability in GitLab that Allows You to Read Arbitrary Server Files
The INCIBE-CERT alerts a critical vulnerability in GitLab (CVE-2026-85706) that allows you to read arbitrary files; update to corrected versions. The INCIBE-CERT entry alerts a critical vulnerability in GitLab that allows you to read arbitrary server files appears first in Moncloa.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium






