CISA incorporó CVE-2026-85706 a su catálogo de vulnerabilidades explotadas, después de que investigadores detectaran sondeos contra servidores GitLab vulnerables. 1
The RegisterPerfect-10 GitLab bug under attack days after patch lands14 sept, 11:302
Cybersecurity DiveMalicious actors already using critical GitLab flaw, CISA and others warn14 sept, 07:463
BleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacks14 sept, 04:06
La falla, con puntuación CVSS 10.0, permite a atacantes no autenticados leer archivos arbitrarios mediante un problema de recorrido de rutas en la API de commits. 1
The RegisterPerfect-10 GitLab bug under attack days after patch lands14 sept, 11:304
Infosecurity MagazineHackers Exploit Maximum Severity Flaw in GitLab14 sept, 07:003
BleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacks14 sept, 04:06
El defecto afecta instalaciones autogestionadas de GitLab CE y EE en ramas anteriores a 19.1.8, 19.2.6 y 19.3.2. 1
The RegisterPerfect-10 GitLab bug under attack days after patch lands14 sept, 11:304
Infosecurity MagazineHackers Exploit Maximum Severity Flaw in GitLab14 sept, 07:00
GitLab publicó esas versiones corregidas el 10 de septiembre y señaló que GitLab.com ya estaba actualizado; los clientes de GitLab Dedicated no necesitan intervenir. 1
The RegisterPerfect-10 GitLab bug under attack days after patch lands14 sept, 11:302
Cybersecurity DiveMalicious actors already using critical GitLab flaw, CISA and others warn14 sept, 07:46
watchTowr observó solicitudes POST dirigidas a /api/v4/projects/{id}/repository/commits/ con parámetros file.path, un indicador para revisar en los registros. 1
The RegisterPerfect-10 GitLab bug under attack days after patch lands14 sept, 11:304
Infosecurity MagazineHackers Exploit Maximum Severity Flaw in GitLab14 sept, 07:003
BleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacks14 sept, 04:06
La explotación puede exponer archivos locales, configuraciones, credenciales y otros secretos almacenados en servidores afectados. 1
The RegisterPerfect-10 GitLab bug under attack days after patch lands14 sept, 11:302
Cybersecurity DiveMalicious actors already using critical GitLab flaw, CISA and others warn14 sept, 07:463
BleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacks14 sept, 04:06
Las agencias civiles federales estadounidenses recibieron hasta el 15 de septiembre para mitigar el riesgo bajo la directiva BOD 26-04. 4
Infosecurity MagazineHackers Exploit Maximum Severity Flaw in GitLab14 sept, 07:003
BleepingComputerCISA: Hackers now exploit max severity GitLab flaw in attacks14 sept, 04:06
GitLab también corrigió CVE-2026-87719, una vulnerabilidad que podía permitir obtener información sensible de servidores Enterprise Edition. 2
Cybersecurity DiveMalicious actors already using critical GitLab flaw, CISA and others warn14 sept, 07:46