High

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

darkreading

Overview

A severe vulnerability identified as CVE-2026-85706 has been discovered in both the GitLab Community Edition and Enterprise Edition. This flaw is categorized as a path traversal vulnerability and carries a maximum CVSS score of 10 out of 10, indicating its potential for serious exploitation. Organizations using affected versions of GitLab could see significant risks to their software supply chains, as attackers could exploit this vulnerability to access sensitive files and data. Companies using these GitLab instances are urged to take immediate action to protect their systems and data. The urgency of addressing this issue is underscored by the potential for attackers to exploit it in real-world scenarios, putting countless users and organizations at risk.

Key Takeaways

  • Affected Systems: GitLab Community Edition, GitLab Enterprise Edition
  • Action Required: Users should apply patches and updates provided by GitLab as soon as they are available.
  • Timeline: Newly disclosed

Original Article Summary

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

Impact

GitLab Community Edition, GitLab Enterprise Edition

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Users should apply patches and updates provided by GitLab as soon as they are available. It is advisable to review system configurations and restrict access to sensitive directories to mitigate risks associated with path traversal vulnerabilities.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability.

Related Coverage

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

The Hacker News

Cisco has issued a warning about a serious vulnerability in its AsyncOS software for the Cisco Secure Email Gateway, identified as CVE-2026-76461. This flaw, which has a CVSS score of 9.8, allows unauthenticated remote attackers to execute root commands due to insufficient validation in the email parsing logic. The vulnerability is currently being exploited in the wild, putting users at significant risk. Organizations using affected versions of the Cisco Secure Email Gateway should take immediate action to protect their systems. This incident underscores the importance of timely updates and vigilance in cybersecurity practices.

Sep 15, 2026

Homebrew 7.0.0 is out, here’s what changed for security

Help Net Security

Homebrew, a popular package manager for macOS and Linux, released version 7.0.0 on Sunday, addressing eight security vulnerabilities in the process. The most critical issue involved a flaw that allowed unsigned removal metadata for casks—Homebrew's method for installing prebuilt applications—to execute commands with elevated privileges (sudo). To mitigate this risk, the development team removed the vulnerable recovery code and the related API accessors that could be exploited. This update is particularly important for developers who rely on Homebrew for managing their software installations, as it helps protect their systems from potential abuse. Users are encouraged to update to the latest version to safeguard against these vulnerabilities.

Sep 15, 2026

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

BleepingComputer

Japan's Digital Agency has reported a significant data breach affecting around 246,000 records containing sensitive personal information of government employees. The breach is linked to a flaw in a Virtual Private Network (VPN), which allowed unauthorized access to these records. This incident raises concerns about the security of government digital infrastructure and the potential for misuse of the exposed data. With personal information at risk, affected individuals may face identity theft or other privacy violations. The agency is urging immediate action to address the vulnerability and protect sensitive information moving forward.

Sep 14, 2026

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

The Hacker News

An attacker gained unauthorized access to the network of 3BB, a major broadband provider in Thailand, using a legitimate remote management tool called MeshCentral. This allowed the attacker to maintain control over internal machines and potentially harvest subscriber credentials. The breach was discovered by the cybersecurity firm Hunt.io, which found an exposed server containing the attacker’s tools and a list of compromised data. This incident raises concerns about the security of management tools and the potential for attackers to exploit legitimate software for malicious purposes. Users of 3BB and similar services should be vigilant about their account security and monitor for any suspicious activity.

Sep 14, 2026

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

The Hacker News

Researchers have identified a new hardware attack named DDRop that compromises memory protection in Intel and AMD's confidential computing systems. This attack allows an unauthorized user, who already has control over the server's software, to manipulate memory writes. By inserting a small circuit, the attacker can cause the processor to read outdated encrypted data as if it were current. This vulnerability poses significant risks for organizations relying on Intel TDX and AMD SEV-SNP technologies for secure computing, as it undermines the confidentiality of sensitive data. Companies using these systems should be aware of the potential for exploitation and take action to secure their environments.

Sep 14, 2026

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

The Hacker News

A Chinese hacking group known as Red Heron has exploited a recently discovered vulnerability in Gitea, a platform for managing Git repositories. This group scanned over 1,300 Gitea instances across multiple countries, successfully compromising 13 organizations in six different nations. Notably, they maintained a separate list of nearly 500 systems based in Taiwan. The rapid exploitation of this vulnerability highlights the risks associated with internet-facing applications, especially when they are not adequately secured. Organizations running Gitea should take immediate action to assess their systems and apply necessary updates to prevent similar attacks.

Sep 14, 2026