{"rows":[{"id":"39ca8c4306a4fa4421dd4eeb40d0c17276a2d1fb","sourceId":"securityaffairs","url":"https://securityaffairs.com/199137/hacking/cisco-warns-of-ongoing-exploitation-of-critical-email-gateway-zero-day.html","title":"Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day","author":"Pierluigi Paganini","publishedAt":1789477232000,"fetchedAt":1789481837891,"feedSummary":"Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL […]","contentStatus":"ok","imageUrl":"https://i0.wp.com/securityaffairs.com/wp-content/uploads/2014/07/cisco-building.jpg?fit=680%2C400&ssl=1","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789481837891,"category":"exploit","severity":"critical","importance":93,"tldr":"Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) is actively exploited for root command execution; CISA added it to KEV.","summary":"Cisco disclosed critical zero-day CVE-2026-76461 (CVSS 9.8) in Secure Email Gateway, remotely exploitable without authentication via crafted emails containing malicious SQL statements, leading to arbitrary command execution with root privileges. The flaw affects physical and virtual appliances regardless of configuration and has no workarounds. Cisco PSIRT confirmed active exploitation, and CISA added the CVE to its KEV catalog on September 14 with a federal remediation deadline of September 17. Admins should review mail_logs for suspicious SQL statements such as 'COPY.*TO PROGRAM'.","keyPoints":["Unauthenticated remote attacker gains root command execution via crafted emails with malicious SQL statements.","Affects all Cisco Secure Email Gateway appliances, physical and virtual; no workarounds exist.","CISA added CVE-2026-76461 to KEV September 14; federal agencies must remediate by September 17.","Detection: grep mail_logs on each cluster device for 'COPY.*TO PROGRAM' entries."],"tags":["cisco","secure-email-gateway","zero-day","cve-2026-76461","kev","cisa","sql-injection","asyncos"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-76461"],"inTheWild":true,"confidence":0.98,"clusterId":"4f81468e254bddc4fc4b8993b04b75ac7df78218","extra":{"hint":null,"related":[],"related_at":1789481837891,"source_weight":1,"related_provider":"bing"},"sourceName":"Security Affairs","sourceHomepage":"https://securityaffairs.com","rank":0,"clusterSize":15,"clusterLatestAt":1789505201000},{"id":"56c4768b21a4e6bd0f96cf876c117e78da455dbc","sourceId":"hn-security","url":"https://www.lawfaremedia.org/article/america%27s-drivers-licence-breach-is-a-national-security-disaster","title":"America's Driver's License Breach Is a National Security Disaster","author":"hn_acker","publishedAt":1789487928000,"fetchedAt":1789492638468,"feedSummary":"26 points · 4 comments on Hacker News","contentStatus":"ok","imageUrl":"https://lawfare-assets-new.azureedge.net/assets/images/default-source/article-images/featured_image/7836.png?sfvrsn=49771b1e_0","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789492638468,"category":"breach","severity":"critical","importance":92,"tldr":"Dark web service Nexus sells 153 million US/Canadian driver's licenses linked to a breach of identity verifier IDScan.","summary":"Krebs on Security revealed a dark web service, Nexus, selling access to 153 million driver's licenses and 3 million travel documents from US and Canadian citizens, roughly 63 percent of all US licenses. Circumstantial evidence links the data to identity verification firm IDScan, which confirmed it is investigating a breach, and the FBI is probing the incident. Licenses belonging to senior US officials, including Pete Hegseth, an FBI assistant director, and Krebs's own contacts were verified as genuine. The exfiltration appears ongoing, with the database growing by nearly 400,000 licenses in a single day, and the data carries significant national security value for foreign intelligence services.","keyPoints":["153M driver's licenses exposed, about 63% of all US licenses","Breach linked to identity verification firm IDScan; FBI investigating","Database grew ~400,000 licenses in one day, indicating ongoing exfiltration","Licenses of senior US officials found and verified as genuine","Data has counterintelligence value comparable to OPM or Anthem thefts"],"tags":["breach","idscan","nexus","driver-license","identity-verification","data-leak","national-security"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.95,"clusterId":"56c4768b21a4e6bd0f96cf876c117e78da455dbc","extra":{"hint":null,"hn_id":"49714547","points":26,"related":[],"comments":4,"related_at":1789492638468,"source_weight":0.9,"discussion_url":"https://news.ycombinator.com/item?id=49714547","related_provider":"bing"},"sourceName":"Hacker News · security","sourceHomepage":"https://news.ycombinator.com","rank":0,"clusterSize":1,"clusterLatestAt":1789487928000},{"id":"4db4c39c14962ba1b188e3851a99b6126b2ea7e6","sourceId":"therecord","url":"https://therecord.media/china-spy-chief-warns-of-us-ai-models","title":"China spy chief points at US AI models in cyber threat warning","author":null,"publishedAt":1789476840000,"fetchedAt":1789478237647,"feedSummary":"China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.","contentStatus":"ok","imageUrl":"http://cms.therecord.media/uploads/China_8e2f51518c.jpg","domain":"cyber","aiStatus":"failed","aiModel":null,"aiAt":1789478237647,"category":"exploit","severity":"critical","importance":90,"tldr":"China spy chief points at US AI models in cyber threat warning","summary":"The Chinese Communist Party’s top intelligence official named two U.S. artificial intelligence models as cybersecurity risks to China’s critical infrastructure, though he did not accuse either of being used in attacks on the country. Chen Yixin, head of the Ministry of State Security, made the comments in the journal of the Cyberspace Administration of China. The ministry oversees China’s…","keyPoints":[],"tags":["exploit"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":[],"inTheWild":false,"confidence":0.3,"clusterId":"4db4c39c14962ba1b188e3851a99b6126b2ea7e6","extra":{"hint":null,"related":[],"related_at":1789478237647,"source_weight":1.4,"related_provider":"bing"},"sourceName":"The Record","sourceHomepage":"https://therecord.media","rank":0,"clusterSize":1,"clusterLatestAt":1789476840000},{"id":"f57fa5b068f1bf947418174bc90887080c20f168","sourceId":"bleepingcomputer","url":"https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/","title":"CISA: Critical VMware RCE flaw now exploited by ransomware gangs","author":"Sergiu Gatlan","publishedAt":1789474592000,"fetchedAt":1789475837526,"feedSummary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]","contentStatus":"ok","imageUrl":"https://www.bleepstatic.com/content/hl-images/2024/11/18/VMware.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789475837526,"category":"exploit","severity":"critical","importance":90,"tldr":"CISA warns ransomware gangs now exploit critical VMware vCenter syslog RCE CVE-2026-59310, already KEV-listed after APT compromises across 47 countries.","summary":"Broadcom patched critical directory traversal flaw CVE-2026-59310 in the vCenter Syslog server on July 29, warning of unauthenticated remote code execution. QUIRSO subsequently found 361 compromised IPs across 47 countries after a suspected APT deployed a reverse SSH tool for persistence and remote access. CISA added the flaw to its KEV catalog with a three-day patch deadline for federal agencies, and over the weekend updated it to flag active abuse by ransomware gangs. Shadowserver tracks over 450 exposed vCenter servers, and CISA has tagged 26 VMware vulnerabilities as exploited in the wild over five years, nine abused by ransomware.","keyPoints":["CVE-2026-59310: critical unauth directory traversal RCE in vCenter Syslog server, patched July 29","Suspected APT compromised 361 IPs in 47 countries using reverse SSH persistence","KEV catalog updated to flag active ransomware gang exploitation","Over 450 vCenter servers currently exposed online per Shadowserver"],"tags":["vmware","vcenter","cve-2026-59310","kev","ransomware","cisa","rce","broadcom"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-59310","CVE-2025-60710","CVE-2025-22225","CVE-2026-22719","CVE-2024-37079"],"inTheWild":true,"confidence":0.95,"clusterId":"f57fa5b068f1bf947418174bc90887080c20f168","extra":{"hint":null,"related":[],"related_at":1789475837526,"source_weight":1.3,"related_provider":"bing"},"sourceName":"BleepingComputer","sourceHomepage":"https://www.bleepingcomputer.com","rank":0,"clusterSize":1,"clusterLatestAt":1789474592000},{"id":"495145696fadc205d3ccc50e0af7bd8634607784","sourceId":"gbhackers","url":"https://gbhackers.com/marimo-rce-flaw/","title":"Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds","author":"Divya","publishedAt":1789466304000,"fetchedAt":1789467436919,"feedSummary":"A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according to the Sysdig Threat Research Team. This vulnerability, tracked as CVE-2026-39987, affects marimo versions up to 0.20.4 and […]\nThe post Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/09/87dbaf96-3149-4a1f-ad11-d9ad7ef218d1-3.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789467436919,"category":"exploit","severity":"critical","importance":72,"tldr":"Attacker exploited unauthenticated marimo WebSocket RCE CVE-2026-39987 to steal AWS credentials and SSH into a bastion host in eight seconds.","summary":"Sysdig Threat Research Team documented a real intrusion exploiting CVE-2026-39987 in marimo (versions up to 0.20.4, fixed in 0.23.0), where the unauthenticated /terminal/ws WebSocket endpoint exposed an interactive shell. Within eight seconds the attacker pulled AWS credentials from Redis, extracted an SSH private key from AWS Secrets Manager via Boto3, and authenticated to a bastion host; over nine hours the operator ran 850+ commands using a staged custom Python toolkit. Blocked EC2 Instance Connect attempts (SendSSHPublicKey to placeholder instance i-0000000000000000) provide a high-confidence detection signal.","keyPoints":["CVE-2026-39987: unauthenticated /terminal/ws WebSocket shell in marimo, fixed in 0.23.0","AWS credential theft to Secrets Manager key retrieval to bastion SSH completed in eight seconds","Attacker staged custom Python automation scripts in /tmp after four hours of development","Two distinct IAM identities used; 850+ interactive commands over nine-hour intrusion","Defenders should hunt /terminal/ws connections, keys in /tmp, and port 4444 callbacks"],"tags":["marimo","rce","websocket","aws","credential-theft","ssh","cloud-security","sysdig"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-39987"],"inTheWild":true,"confidence":0.9,"clusterId":"12c1fe8353db3358bdf9c70354a3aa578c7fd30c","extra":{"hint":null,"source_weight":0.7},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","rank":0,"clusterSize":4,"clusterLatestAt":1789473148000},{"id":"a4d6d653b895f80fbff5b8077a65f2753aa57ac6","sourceId":"gbhackers","url":"https://gbhackers.com/red-heron-hackers-exploit-critical-gitea-rce/","title":"Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit","author":"Divya","publishedAt":1789470977000,"fetchedAt":1789471037198,"feedSummary":"A Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source code, harvest credentials, establish persistent access, and move laterally within victim infrastructures. Researchers from the Acronis Threat Research Unit (TRU) have linked this operation to a newly documented Linux implant called JITTERLY, […]\nThe post Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.","contentStatus":"ok","imageUrl":"https://gbhackers.com/wp-content/uploads/2026/09/f950c2cb-ca5b-4663-9a93-d44f0264a059-1.webp","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789471037198,"category":"threat-actor","severity":"critical","importance":84,"tldr":"PRC-linked Red Heron exploits critical Gitea RCE CVE-2026-60004 to steal source code and deploy JITTERLY implant with SIXZUT LD_PRELOAD rootkit; victims span five countries.","summary":"Acronis Threat Research Unit attributes a campaign to Chinese-speaking threat actor Red Heron, which weaponized CVE-2026-60004, a CVSS 9.8 RCE in Gitea versions 1.17 through 1.27.0, patched in 1.27.1 on July 27, 2026. The actor built an automated exploitation framework after a public PoC appeared, scanned 1,386 internet-exposed Gitea instances across seven countries, and separately listed 477 Taiwan-based systems across defense, energy, elections, and AI sectors. Confirmed victims include organizations in Canada, Argentina, Taiwan, the US, and Sri Lanka, with a Canadian renewable-energy firm hit in 22 sessions and a Taiwanese industrial automation firm losing hundreds of repositories including SCADA/HMI tools. Red Heron deploys the JITTERLY Linux implant (30+ commands, AES-128-GCM, Adaptix-like protocol) and the SIXZUT LD_PRELOAD rootkit disguised as libglthread.so.2, and moved laterally into a Synology/Proxmox environment to steal VM backups.","keyPoints":["Red Heron automated exploitation of Gitea CVE-2026-60004 (CVSS 9.8) after public PoC release.","JITTERLY C++ implant runs 30+ commands and uses AES-128-GCM encrypted C2.","SIXZUT rootkit hides via /etc/ld.so.preload as libglthread.so.2, evading admin tools.","Confirmed compromises in Canada, Argentina, Taiwan, US, and Sri Lanka; source code and credentials stolen.","Lateral movement into Proxmox cluster risked exposure of full VM disk image backups.","TRU assesses moderate confidence PRC linkage; no known APT group association yet."],"tags":["gitea","rce","red heron","jitterly","sixzut","ld_preload","prc","espionage"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-60004"],"inTheWild":true,"confidence":0.75,"clusterId":"8cbdb00573dcd2cf13f69bf1c79e8dae1bebb9b2","extra":{"hint":null,"related":[],"related_at":1789471037198,"source_weight":0.7,"related_provider":"bing"},"sourceName":"GBHackers","sourceHomepage":"https://gbhackers.com","rank":0,"clusterSize":3,"clusterLatestAt":1789470977000},{"id":"345bbaad081d3405daf436c11c37ce750fab4ab1","sourceId":"securityaffairs","url":"https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html","title":"One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire","author":"Pierluigi Paganini","publishedAt":1789467460000,"fetchedAt":1789472237290,"feedSummary":"Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]","contentStatus":"ok","imageUrl":"https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/09/image-41.png?resize=811%2C402&#038;ssl=1","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789472237290,"category":"threat-actor","severity":"critical","importance":85,"tldr":"Two China-linked APT groups reused identical Chrome/Windows zero-day chain against NGOs, deploying GRIMWIDGE backdoor and LONGTALE credential-stealing extension.","summary":"Volexity reports that China-linked actors UTA0560 and JungleBamboo (APT31/TA412) ran byte-identical Chrome/Windows exploit chains against NGOs starting September 1, 2026, combining Chrome type confusion CVE-2026-85046, WebAssembly sandbox escape CVE-2026-87491, and Windows kernel flaw CVE-2026-85880. The Chrome bug was fixed in Chromium source but not yet shipped to Chrome users, making it an effective zero-day with an unusual patch gap. UTA0560 delivered the in-memory GRIMWEDGE JScript backdoor, while JungleBamboo deployed the SUPERSTOMP loader installing LONGTALE, a malicious Chrome extension disguised as Google Gemini that steals cookies, session tokens, and keystrokes. Volexity assesses with low confidence the exploit chain was sold or shared among different Chinese end-users.","keyPoints":["Identical shellcode across campaigns suggests shared or sold exploit chain.","Three-CVE chain achieves V8 sandbox escape and Windows kernel code execution.","Chrome patch gap: fix in Chromium source but unpatched in Chrome during attacks.","LONGTALE Chrome extension bypasses profile integrity checks via legacy HMAC fallback."],"tags":["chrome","zero-day","apt31","volexity","espionage","v8","backdoor","infostealer"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-85046","CVE-2026-87491","CVE-2026-85880"],"inTheWild":true,"confidence":0.82,"clusterId":"bc17f35df3d0672cd369d167d396f3f577ce8fe4","extra":{"hint":null,"related":[],"related_at":1789472237290,"source_weight":1,"related_provider":"bing"},"sourceName":"Security Affairs","sourceHomepage":"https://securityaffairs.com","rank":0,"clusterSize":20,"clusterLatestAt":1789467460000},{"id":"01e94fc178c5641a9ef7e43967ef0e8d1ba9ff3f","sourceId":"bleepingcomputer","url":"https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/","title":"Cisco patches Secure Email Gateway zero-day exploited in attacks","author":"Sergiu Gatlan","publishedAt":1789457469000,"fetchedAt":1789457836178,"feedSummary":"Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]","contentStatus":"ok","imageUrl":"https://www.bleepstatic.com/content/hl-images/2026/08/11/Cisco.jpg","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789457836178,"category":"exploit","severity":"critical","importance":90,"tldr":"Cisco patches actively exploited Secure Email Gateway zero-day CVE-2026-76461 enabling unauthenticated root command execution; CISA adds it to KEV.","summary":"Cisco disclosed that a critical zero-day (CVE-2026-76461) in the email parsing logic of AsyncOS for Secure Email Gateway is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary SQL statements that lead to root-level command execution on virtual and physical appliances. CISA added the flaw to its KEV catalog and ordered federal agencies to patch within three days, by September 17. Cisco also patched four other critical SEG/SEWM vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) with no evidence of exploitation, and shared IOCs including suspicious SQL statements in mail_logs.","keyPoints":["CVE-2026-76461 is actively exploited as a zero-day in Cisco Secure Email Gateway.","Unauthenticated attackers can gain root command execution via crafted email with SQL statements.","CISA KEV listing requires federal patching by September 17.","Shadowserver tracks 400+ internet-exposed Secure Email Gateway appliances.","Four additional critical SEG/SEWM flaws patched with no observed exploitation."],"tags":["cisco","secure-email-gateway","asyncos","zero-day","kev","cisa","sql-injection","rce"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-76461","CVE-2026-76440","CVE-2026-76441","CVE-2026-20353","CVE-2026-76443","CVE-2025-20393"],"inTheWild":true,"confidence":0.97,"clusterId":"01e94fc178c5641a9ef7e43967ef0e8d1ba9ff3f","extra":{"hint":null,"related":[{"url":"https://www.cisco.com/","title":"AI Infrastructure, Secure Networking, and Software Solutions - Cisco","source":"cisco.com","snippet":"Cisco is a worldwide technology leader powering an inclusive future for all. Learn more about our products, services, solutions, and innovations.","publishedAt":1789376160000}],"related_at":1789457836178,"source_weight":1.3,"related_provider":"bing"},"sourceName":"BleepingComputer","sourceHomepage":"https://www.bleepingcomputer.com","rank":0,"clusterSize":1,"clusterLatestAt":1789457469000},{"id":"ca0799c3cfb3b48ebca9c7a552592d46fcb16c06","sourceId":"csoonline","url":"https://www.csoonline.com/article/4221934/a-maximum-severity-gitlab-flaw-could-turn-your-ci-cd-server-into-an-attackers-treasure-trove.html","title":"A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove","author":null,"publishedAt":1789433575000,"fetchedAt":1789433834653,"feedSummary":"Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity.\nCVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported.\nThreat actors could exploit it “under certain conditions” and read arbitrary files (credentials, secrets, and other sensitive data) on vulnerable GitLab servers.\nThe company has fixed the vulnerability, which impacts GitLab Community Edition (CE) and…","contentStatus":"ok","imageUrl":"https://www.csoonline.com/wp-content/uploads/2026/09/4221934-0-07329500-1789433588-Prompt-Injektionen-bei-GitLab-Duo-verbreiten-Schadcode.jpg?quality=50&strip=all","domain":"cyber","aiStatus":"done","aiModel":"glm-5.3","aiAt":1789433834653,"category":"exploit","severity":"critical","importance":88,"tldr":"GitLab patched maximum-severity CVE-2026-85706, an unauthenticated path traversal enabling arbitrary file reads; CISA added it to KEV amid observed in-the-wild probes.","summary":"CVE-2026-85706 is a CVSS 10.0 path traversal in GitLab's repository commits API caused by improper confinement and missing authentication enforcement, allowing arbitrary file reads in a single unauthenticated HTTP request. It affects GitLab CE and EE versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, and was reported via GitLab's HackerOne bug bounty. CISA added the flaw to its Known Exploited Vulnerabilities catalog, and watchTowr Intel reports already observing in-the-wild probes; GitLab is used by roughly 50% of the Fortune 100 with over 50 million registered users. Defenders are advised to patch immediately, rotate any exposed secrets, and hunt logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.path parameters.","keyPoints":["CVE-2026-85706 scores 10.0; unauthenticated path traversal in repository commits API","Affects GitLab CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2","CISA added it to KEV; watchTowr already observing in-the-wild probes","Exposed files may hold secrets and credentials requiring rotation","Hunt for POST requests to repository/commits API with file.path parameters"],"tags":["gitlab","cve-2026-85706","path-traversal","cisa-kev","ci-cd","devsecops","patch"],"entities":{"malware":[],"vendors":[],"victims":[],"products":[],"ai_models":[],"countries":[],"organizations":[],"threat_actors":[]},"cves":["CVE-2026-85706"],"inTheWild":true,"confidence":0.75,"clusterId":"e191935ce3fc346dc71308f313bb7fff27913ac7","extra":{"hint":null,"related":[],"related_at":1789433834653,"source_weight":0.9,"related_provider":"bing"},"sourceName":"CSO Online","sourceHomepage":"https://www.csoonline.com","rank":0,"clusterSize":17,"clusterLatestAt":1789433575000}],"total":9,"page":1,"pageSize":40,"serverTime":1789507422718}