GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

2026-09-11T19:23:59Z9cc08e961a2002afe6a9d135496d68df35334548b7d1256e052994ba23c30a56
CVE-2026-20079CVE-2026-85706CVE-2026-87491AI-assisted-attacksAndroid-malwareChromeCisco-FMCGitLabJFrog-ArtifactoryPaperCutactive-exploitationcloud-and-AI-securitycredential-theftcritical-infrastructurecyber-espionageinfostealerspatchingphishingransomwarestate-sponsored-threatssupply-chain-securityvulnerability-managementzero-day

What happened

The document is a September 2026 security-news feed covering actively exploited vulnerabilities, critical product flaws, ransomware and espionage activity, AI-assisted attacks, malware campaigns, exposed administrative credentials, and cryptocurrency scams. The highest-risk items include a CVSS 10 GitLab path-traversal file-read flaw under in-the-wild probing, Cisco FMC authentication bypass exploitation, actively exploited PaperCut vulnerabilities, Chrome V8 zero-day exploitation, and chained JFrog Artifactory flaws enabling administrator takeover and backdoor deployment.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9cc08e961a2002afe6a9d135496d68df35334548b7d1256e052994ba23c30a56
Enrichment time
2026-09-11T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure · Baitaphish