Perfect-10 GitLab bug under attack days after patch lands
CISA confirms active exploitation of CVSS 10.0 GitLab path traversal flaw CVE-2026-85706 days after patches shipped, enabling unauthenticated arbitrary file reads.
CISA added CVE-2026-85706, a maximum-severity 10.0 CVSS path traversal flaw in GitLab's repository commits API, to its Known Exploited Vulnerabilities catalog and confirmed active exploitation. The bug allows unauthenticated attackers to read arbitrary files, including configuration data and credentials, from self-managed GitLab CE/EE servers via a single HTTP POST request. GitLab shipped fixes on September 10 in versions 19.3.2, 19.2.6, and 19.1.8, covering versions 18.7 through 19.3. watchTowr is observing probes against internet-facing instances and warns widespread exploitation is likely to follow quickly.
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
Cisco Talos confirms nation-state (Sandworm) and ransomware (Qilin) actors actively exploit CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center.
CVE-2026-20079 is a critical unauthenticated authentication bypass in the FMC web interface allowing root-level script and command execution via crafted HTTP requests; CVE-2026-20316 stems from static hard-coded credentials enabling unauthenticated logins. Cisco Talos detailed three intrusion clusters: web shell and JAR deployment for credential theft, a Sandworm-attributed reverse shell and credential-harvesting implant, and a suspected Qilin ransomware operator chain. Cisco urges immediate hotfixes ahead of a comprehensive hardening release the week of September 16, or taking the FMC management interface offline.