GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
2026-09-12T07:23:58Z•6b40b06efc458ac17442bae16746a64c90d04e41a40c6d260368735bd2b307e1
CVE-2026-20079CVE-2026-85706CVE-2026-87491AI-assisted-attacksAndroid-malwareKEVactive-exploitationauthentication-bypasscloud-and-AI-securitycredential-theftespionagepath-traversalphishingransomwareremote-code-executionstate-sponsored-threatssupply-chain-securityvulnerability-disclosurezero-day
What happened
Security news roundup covering actively exploited vulnerabilities, critical unauthenticated access and remote-code-execution flaws, ransomware and espionage campaigns, AI-assisted attacks, malicious Android applications, exposed administrative credentials, and abuse of AI model access tokens. Highest-risk items include the CVSS 10 GitLab path traversal flaw under in-the-wild probing, Cisco FMC authentication bypass exploitation, actively exploited PaperCut flaws, critical Check Point VPN certificate vulnerabilities, Chrome V8 exploitation, and attacks against JFrog Artifactory and other public
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 6b40b06efc458ac17442bae16746a64c90d04e41a40c6d260368735bd2b307e1
- Enrichment time
- 2026-09-12T07:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.