GitLab patches critical path traversal vulnerability CVE-2026-85706
GitLab released urgent patches on September 11, 2026 to address CVE-2026-85706 (CVSS 10.0), a maximum-severity path traversal flaw in the repository commits API affecting self-managed installations. The vulnerability allows unauthenticated attackers to read arbitrary files; CISA added it to the exploited vulnerabilities catalog with active in-the-wild probes within days.