Critical GitLab Path Traversal Vulnerability (CVE-2026-85706) Actively Exploited
A CVSS 10.0 flaw in GitLab Community/Enterprise Edition allows unauthenticated arbitrary file-read attacks via repository commits API. GitLab patched September 10; CISA confirmed in-the-wild exploitation by September 11. Self-managed instances remain at risk with no workaround.