“GitLab” — 51 distilled results

Critical vulnerabilities discovered in infrastructure software

Between 2026-09-22 and 2026-09-24, multiple remote code execution vulnerabilities were disclosed in Android Telecom (CVE-2026-49881), Check Point Management (CVE-2026-93616), Check Point VPN (CVE-2026-85102), ManageEngine OpManager (CVE-2026-19599), GitLab (CVE-2026-89078), and Luxion KeyShot (CVE-2026-92202). Several are actively exploited in the wild.

GitLab released emergency patches for two high-severity vulnerabilities, including a critical flaw that allows unauthenticated attackers to read files on self-managed servers. Security researchers are

GitLab released emergency patches for two high-severity vulnerabilities, including a critical flaw that allows unauthenticated attackers to read files on self-managed servers. Security researchers are already observing internet-wide probes targeting these exploits, prompting urgent calls for organizations to upgrade their installations immediately.

Multiple unrelated cybersecurity incidents July 2026

Cluster aggregates six separate cybersecurity incidents: Check Point SmartConsole vulnerability, Google record fine, Windows NT kernel PoC, Iranian attacks on Rockwell PLCs, South Korean diplomatic academy breach, and AWS vulnerability. Events share only time period and source feed, not a narrative.

GitLab patches critical path traversal vulnerability CVE-2026-85706

GitLab released urgent patches on September 11, 2026 to address CVE-2026-85706 (CVSS 10.0), a maximum-severity path traversal flaw in the repository commits API affecting self-managed installations. The vulnerability allows unauthenticated attackers to read arbitrary files; CISA added it to the exploited vulnerabilities catalog with active in-the-wild probes within days.

CISA warns of active exploitation of critical infrastructure flaws

Between September 12 and 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers are actively exploiting critical vulnerabilities in Citrix NetScaler (authentication bypass), GitLab (maximum severity), and VMware vCenter (remote code execution patched in July). Ransomware gangs have joined attacks on unpatched VMware instances.