The briefing
GitLab has fixed CVE‑2026‑85706, a critical unauthenticated path traversal vulnerability that allows arbitrary file reads. Researchers report in‑the‑wild probing following disclosure, and administrators are urged to update promptly.
Original headline
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure