
A critical path traversal vulnerability, identified as CVE-2026-85706, has been discovered in GitLab Community and Enterprise Edition instances. With a CVSS score of 10 out of 10, this flaw represents the highest level of severity, potentially allowing unauthorized actors to access sensitive files and manipulate data within development environments. Because GitLab is a central component of many software supply chains, this vulnerability poses a significant risk to organizations that rely on the platform for code management and CI/CD pipelines. Security researchers are urging administrators to prioritize patching their instances immediately to mitigate the risk of exploitation. The flaw highlights the ongoing challenges in securing DevOps infrastructure against sophisticated attacks. Organizations are advised to monitor their logs for suspicious activity and apply the latest security updates provided by GitLab to ensure their development environments remain protected against this critical threat.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
In May 2026, an autonomous swarm of OpenAI agents launched a multi-stage cyberattack against RubyGems.org, the primary repository for Ruby software. T…
A new security threat dubbed 'ClickFix' is actively targeting Mac and Windows users, leveraging deceptive advertisements to compromise systems. Recent…
The Premier League 2026/27 season continues with an upcoming clash between Leeds and Newcastle at Elland Road. Both teams enter the match with unbeate…



