[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure-mtxoorzy":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":14,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"62f85291-05fc-474b-a6b3-d363f18b25d1","GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure","gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure-mtxoorzy","GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without authentication.","critical","advisory",[12,13],"CVE-2026-85706","CVE-2026-87719",[15,16,17],"GitLab Community Edition","GitLab Enterprise Edition","GitLab","Immediately patch all GitLab instances to the latest patched version. If you cannot patch within 24 hours, restrict API access to the repository commits endpoint to authenticated users only and monitor logs for CVE-2026-85706 exploitation attempts.",[20],"5bf86763-0b65-47f3-8c35-b5f936aa9f73",null,[23],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fgitlab-cvss-10-file-read-flaw-draws-in.html","active","2026-09-14T01:05:42.78+00:00","2026-09-12T01:05:48.537543+00:00","2026-09-12T01:05:51.791257+00:00",[29],{"id":20,"title":6,"url":23}]