The most serious flaw, CVE-2026-85706, carries a CVSS score of 10.0 and affects both Community Edition and Enterprise Edition. GitLab said improper path confinement and missing authentication ...
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public ...
GitLab has released security updates to address multiple vulnerabilities in the company's DevSecOps platform, including ones enabling attackers to take over accounts and inject malicious jobs in ...
GitLab has patched a high-severity two-factor authentication bypass impacting community and enterprise editions of its software development platform. Tracked as CVE-2026-0723, this vulnerability stems ...