A critical path traversal vulnerability (CVE-2026-85706) in GitLab's repository commits API, rated CVSS 10.0, has been actively exploited within 24 hours of its disclosure. This flaw allows attackers to read sensitive files without authentication, potentially exposing credentials and configuration data. Organizations are urged to patch immediately or restrict public access, and to investigate logs for signs of exploitation and rotate compromised credentials.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



