Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
3 results for “CVE-2026-85706”
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
A critical path traversal vulnerability (CVE-2026-85706) with a maximum CVSS score of 10.0 has been disclosed in GitLab CE and EE, enabling unauthorized file system access that could compromise software supply chains.
Sep 15, 2026
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab patched a critical CVSS 10.0 path traversal vulnerability (CVE-2026-85706) in its repository commits API that enabled unauthenticated remote file reading, with evidence of active exploitation attempts observed within hours of disclosure.
Sep 11, 2026
GitLab urges users to patch max severity path traversal flaw
GitLab disclosed and urged immediate patching of a critical path traversal vulnerability (CVE-2026-85706) that could allow unauthorized file system access on affected servers.
Sep 11, 2026