[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fb0G9HYZKBQOWD9_MY_cllQvX97O0bteSv-Ukaln_sOs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"7ce20464-dcc0-4650-ac18-79c6f031e98e","gitlab-cvss-10-path-traversal-flaw-exploited-in-the-wild","5bf86763-0b65-47f3-8c35-b5f936aa9f73","GitLab CVSS 10 Path Traversal Flaw Exploited in the Wild","A critical CVSS 10.0 path traversal vulnerability in GitLab's repository commits API allows unauthenticated attackers to read arbitrary files from affected servers, including credentials and sensitive configuration data. The fact that in-the-wild probes began almost immediately after public disclosure highlights how quickly threat actors operationalize newly published CVEs. A second critical insecure deserialization flaw compounds the risk, potentially enabling remote code execution. Organizations running unpatched GitLab instances — especially internet-facing ones — are at severe risk of credential theft and full system compromise. This incident underscores that delay in patching critical-severity vulnerabilities is no longer measured in weeks but in hours.","**Immediate Actions:**\n- Apply GitLab's official patches for CVE-2026-85706 and CVE-2026-87719 to all affected instances without delay.\n- Temporarily restrict unauthenticated access to the GitLab repository commits API at the network or WAF level if patching cannot be completed immediately.\n- Rotate all credentials, tokens, and secrets stored on or accessible by affected GitLab servers as a precautionary measure.\n\n**Detection Measures:**\n- Review server and API access logs for anomalous path traversal patterns (e.g., `..\u002F` sequences) targeting the commits API endpoint.\n- Deploy or tune IDS\u002FIPS signatures to detect exploitation attempts against CVE-2026-85706 and CVE-2026-87719 in real time.\n- Enable alerting on unexpected file-read activity or deserialization errors in application logs.\n\n**Long-Term Improvements:**\n- Implement a formal emergency patching SLA (e.g., ≤24 hours) for CVSS 9.0+ vulnerabilities affecting internet-facing infrastructure.\n- Maintain a continuously updated asset inventory to ensure all GitLab instances — including shadow IT deployments — are accounted for and patched.\n- Enforce network segmentation so that GitLab servers are isolated from broader internal networks, limiting lateral movement if compromised.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","CIS Control 4: Secure Configuration of Enterprise Assets","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 SI-10: Information Input Validation","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","NIST CSF RS.MI-3: Newly Identified Vulnerabilities Mitigated","OWASP Top 10 A01: Broken Access Control","OWASP Top 10 A08: Software and Data Integrity Failures (Insecure Deserialization)","ITIL Change Management: Emergency Change Procedure","published","2026-09-11T18:21:19.904412+00:00","2026-09-11T18:21:19.806+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fgitlab-cvss-10-file-read-flaw-draws-in.html","gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure-a8b895","GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]