<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure — Live Feed</title><link>https://www.live-feeds.com/feed/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure</link><atom:link xmlns:atom="http://www.w3.org/2005/Atom" href="https://www.live-feeds.com/feed/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure/rss.xml" rel="self" type="application/rss+xml"/><description>Continuously updated, source-cited coverage.</description>
<item><title>CISA Adds Critical GitLab File-Read Flaw to Known Exploited Vulnerabilities List</title><link>https://www.live-feeds.com/feed/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure</link><guid isPermaLink="false">https://www.live-feeds.com/feed/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure#u69700</guid><pubDate>Wed, 16 Sep 2026 02:31:32 +0000</pubDate><description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. This maximum-severity path traversal flaw carries a CVSS score of 10.0 and allows unauthenticated attackers to read arbitrary files via a single HTTP request to the commits-API. Malicious actors are actively exploiting the vulnerability to access sensitive files within software development environments. CISA and other security entities warn that these attacks are ongoing, urging immediate patching to prevent unauthorized data access.Why it mattersThe vulnera</description></item>
<item><title>GitLab CVSS 10 Flaw Triggers In-the-Wild Probes</title><link>https://www.live-feeds.com/feed/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure</link><guid isPermaLink="false">https://www.live-feeds.com/feed/gitlab-cvss-10-file-read-flaw-draws-in-the-wild-probes-after-disclosure#u67620</guid><pubDate>Mon, 14 Sep 2026 07:50:06 +0000</pubDate><description>GitLab urges users to patch a maximum-severity path traversal vulnerability carrying a CVSS score of 10.0, identified as CVE-2026-85706. The flaw allows unauthenticated attackers to read arbitrary files using a single HTTP request via the commits-API. Within hours of disclosure, security researchers and threat actors initiated internet-wide probing and active exploitation of the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency warned that hackers are now exploiting the max severity GitLab flaw in attacks.Why it mattersGitLab issued emergency security updates to address </description></item>
</channel></rss>