Home / Sep 15, 2026 / Story
0
#2 Dark Reading general September 14, 2026 at 20:19 UTC

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

By Rob Wright

AI Summary

CVE-2026-85706 is a CVSS 10.0 path traversal vulnerability affecting both GitLab Community Edition and Enterprise Edition, and CISA has confirmed active exploitation in the wild. The maximum severity score and GitLab's widespread use in software development pipelines makes this a critical supply chain risk requiring immediate patching.

Relevance score: 91.0/100

# More from September 15

  1. 10
    Microsoft’s Patching Schneier on Security