daily cyber × ai intelligence

index

tagged

[CVE-2026-85706]

3 editions · 3 items

September 13, 2026

  • GitLab's CVSS 10.0 path traversal is now on KEV, added Friday afternoon (CyberScoop, earlier coverage). CVE-2026-85706 lets an unauthenticated attacker read any file on the server in a single HTTP request and affects every release from 18.7 through 19.1.8 plus the 19.2 and 19.3 lines. A second EE-only flaw, CVE-2026-87719 (CVSS 9.9), lets a Duo Chat user coax the server into returning Advanced Search settings and stored passwords. watchTowr points defenders at POST requests under /api/v4/projects/{id}/repository/commits/ carrying a file.path parameter; @Chris_L_Elliott adds that an upgrade alone doesn't prove no exfiltration — hunt the file reads and rotate exposed secrets. · Vulnerabilities & Exploitation

in Artifactory Chains Give Attackers Admin in Under Five Minutes

September 12, 2026

  • GitLab CVE-2026-85706 is now confirmed exploited, not merely scanned. CERT-SE says CISA added the CVSS 10.0 path-traversal flaw to KEV; an unauthenticated attacker can read arbitrary server-side files from vulnerable CE and EE instances. Fixed release lines are 19.1.8, 19.2.6, and 19.3.2, and a public PoC is available. Patch and examine logs from exposed servers (earlier coverage). · Vulnerabilities & Active Exploitation

in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack