daily cyber × ai intelligence

index

tagged

[CVE-2026-87719]

1 edition · 1 item

September 13, 2026

  • GitLab's CVSS 10.0 path traversal is now on KEV, added Friday afternoon (CyberScoop, earlier coverage). CVE-2026-85706 lets an unauthenticated attacker read any file on the server in a single HTTP request and affects every release from 18.7 through 19.1.8 plus the 19.2 and 19.3 lines. A second EE-only flaw, CVE-2026-87719 (CVSS 9.9), lets a Duo Chat user coax the server into returning Advanced Search settings and stored passwords. watchTowr points defenders at POST requests under /api/v4/projects/{id}/repository/commits/ carrying a file.path parameter; @Chris_L_Elliott adds that an upgrade alone doesn't prove no exfiltration — hunt the file reads and rotate exposed secrets. · Vulnerabilities & Exploitation

in Artifactory Chains Give Attackers Admin in Under Five Minutes