
GitLab CVSS 10.0 RCE - CVE-2026-85706 Patch Now
CVE-2026-85706 GitLab CVSS 10.0 path traversal enables unauthenticated RCE. Plus Cisco FMC zero-day exploited by Qilin and dual Check Point VPN 9.8s.
Posts tagged: Cybersecurity

CVE-2026-85706 GitLab CVSS 10.0 path traversal enables unauthenticated RCE. Plus Cisco FMC zero-day exploited by Qilin and dual Check Point VPN 9.8s.

Passkey-themed social engineering compromises Entra ID with MFA persistence. Plus SPIFFE identity spoofing in K8s and Cisco FMC CVE-2026-20079 exploitation.

CVE-2026-20079 Cisco FMC pre-auth RCE actively exploited with Sept 12 CISA deadline. WatchGuard Firebox in ransomware chains.

FreeIPA exploit chain gives anonymous users admin access to Linux domains. ChatGPT OAuth exfiltration and autonomous AI credential harvesting raise the bar.

Microsoft ships record 974 CVE fixes with two exploited zero-days CVE-2026-81963 and CVE-2026-85880. SAP OVERPASS CVSS 10 RCE and N-central KEV deadline Fr.

N-able N-central gets its 5th max-severity RCE hotfix in 5 weeks. CVE-2026-75650 Magento zero-day drops Rust backdoors. 220M travel records exposed.

MikroTik RouterOS SSH chain exploited since Sept 2. N-able N-central CVSS 10 RCE gets 4th hotfix. Adobe Commerce zero-day backdoors stores.

N-able N-central CVSS 10.0 RCE exploited in the wild, fourth patch in five weeks. Citrix NetScaler auth bypass CVE-2026-19490 and JetBrains CI/CD breach.

Token researchers map 39 passkey bypass methods exploiting enrollment and recovery flows. CrowdStrike Falcon zero-day PoC public.

CVE-2026-85046 Chrome V8 type confusion exploited in the wild. Plus 12-year PostgreSQL backdoor CVE-2026-6471 and Cisco Nexus 9000 CVSS 9.8 RCE.