The Hacker News · 9/11/2026

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Maximum-severity path traversal vulnerability (CVE-2026-85706) in GitLab repository API exploited within hours of disclosure, allowing unauthenticated file read.

Read original coverage