Serial Number: AV26-917 Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 | GitLab Docs GitLab release notes | GitLab Docs CISA KEV: CVE-2026-85706
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop .
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek .
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
Serial Number: AV26-877 Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.v2544b_ca_19b_97 Jenkins File Parameter Plugin Prior to or equal to 425.v3fa_801681b_5e Jenkins GitLab Plugin Prior to or equal to 1.9.16 Jenkins LDAP Plugin Prior to or equal to 807.809.vd3a_4e5e4ec98 Jenkins Microsoft Entra ID (previously Azure AD) Plugin Prior to or equal to 710.v0b_ff8e9cc2d2 Jenkins Parameterized Remote Trigger Plugin Prior to or equal to 3.2.2 Jenkins Performance Plugin Prior to or equal to 1015.v09ca_52b_3370e Jenkins Pipeline: Build Step Plugin Prior to or equal to 599.v4b_67ea_11b_152 Jenkins SAML Plugin Prior to or equal to 4.618.v441a_27fa_46d2 Jenkins Script Security Plugin Prior to or equal to 1412.v7737b_3405f86 Jenkins TICS Plugin Prior to or equal to 2025.1.1 Jenkins ThinBackup Plugin Prior to or equal to 2.1.4 Jenkins XebiaLabs XL Deploy Plugin Prior to or equal to 26.1.0 Jenkins update-center2 Prior to or equal to 3.18.3 The Cyber Centre encourages use