<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure]]></title><description><![CDATA[<p dir="auto"><strong>GitLab</strong> has shipped patches for multiple security issues, including a maximum-severity flaw that attackers began probing in the wild within hours of public disclosure.</p>
<p dir="auto">The most serious issue is <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-85706" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-85706</a></strong>, which carries a <strong>CVSS score of 10.0</strong>. It is a path traversal vulnerability in the repository commits API that could let an <strong>unauthenticated</strong> user read arbitrary files from the GitLab server.</p>
<p dir="auto">Details on affected versions and official remediation guidance were not included in the source report, so administrators should consult GitLab's own advisory and apply the available patches as soon as possible. Given the maximum severity rating and evidence of active probing, treating this as an urgent patch is advisable.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has anyone seen probe attempts against their GitLab instance yet, and how quickly are you planning to roll out the fix?</p>
]]></description><link>https://xploitlk.com/topic/303/critical-gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:34:07 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/303.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 12 Sep 2026 00:30:18 GMT</pubDate><ttl>60</ttl></channel></rss>