GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

2026-09-12T07:23:58Z6b40b06efc458ac17442bae16746a64c90d04e41a40c6d260368735bd2b307e1
CVE-2026-20079CVE-2026-85706CVE-2026-87491AI-assisted-attacksAndroid-malwareKEVactive-exploitationauthentication-bypasscloud-and-AI-securitycredential-theftespionagepath-traversalphishingransomwareremote-code-executionstate-sponsored-threatssupply-chain-securityvulnerability-disclosurezero-day

What happened

Security news roundup covering actively exploited vulnerabilities, critical unauthenticated access and remote-code-execution flaws, ransomware and espionage campaigns, AI-assisted attacks, malicious Android applications, exposed administrative credentials, and abuse of AI model access tokens. Highest-risk items include the CVSS 10 GitLab path traversal flaw under in-the-wild probing, Cisco FMC authentication bypass exploitation, actively exploited PaperCut flaws, critical Check Point VPN certificate vulnerabilities, Chrome V8 exploitation, and attacks against JFrog Artifactory and other public

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
6b40b06efc458ac17442bae16746a64c90d04e41a40c6d260368735bd2b307e1
Enrichment time
2026-09-12T07:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure · Baitaphish