Preview image for a blog post

GitLab's Critical CVE-2026-85706: Unauthenticated File-Read Flaw Under Active Exploitation

GitLab's CVSS 10.0 path traversal vulnerability (CVE-2026-85706) allows unauthenticated file-reads, now actively probed in the wild.