CISA: Hackers now exploit max severity GitLab flaw in attacks
2026-09-14T07:23:21Z•2b3028479ab34d439ad649334e2c8bc2822fa9477c5e7b57ba878970f7dfe46f
CVE-2026-51990CVE-2026-85102CVE-2026-85103CVE-2026-85706AI-abuseAndroid-malwareCheck-Point-VPNGitLabJFrog-ArtifactoryMicrosoft-365active-exploitationauthentication-bypassbackdoorcredential-theftcritical-vulnerabilitiesdata-breachmalwarepath-traversalphishingransomwaresupply-chain-risk
What happened
A BleepingComputer security-news feed covering active exploitation of critical vulnerabilities, phishing and credential theft, malware campaigns, data breaches, ransomware, and abuse of trusted AI platforms. Notable items include in-the-wild exploitation of a maximum-severity GitLab path traversal flaw, imminent exploitation of critical Check Point VPN vulnerabilities, Artifactory exploitation leading to backdoor deployment, and targeted Microsoft 365 phishing campaigns.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2b3028479ab34d439ad649334e2c8bc2822fa9477c5e7b57ba878970f7dfe46f
- Enrichment time
- 2026-09-14T07:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.