Výsledky hledání

výrobce: GitLab× typ: novinka v produktu× v celém archivu zrušit filtry

5 karet z 6 položek CZ · EN/orig

1

SPOJENO PŘES CVE GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat

GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…

KEV ✓ EPSS 0.15 CVE-2026-85706 GitLab veřejná správa CZ NL CA US

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu

· CSIRT.CZ (CZ.NIC) · GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat · NCSC-NL · NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions · Cyber Centre Kanada · GitLab security advisory (AV26-917) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVE-2026-85706)

1

SPOJENO PŘES CVE CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…

KEV ✓ EPSS 0.15 CVSS 10.0 CVE-2026-85706 CVE-2026-87719 GitLab US SE

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

· Rapid7 · CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild · CERT-SE · GitLab rättar kritiska sårbarheter

1

GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-85706, CVE-2026-87719, CVE-2026-88765, CVE-2026-79708, CVE-2026-78252, CVE-2026-13210, CVE-2025-14871, CVE-2026-1168, CVE-2024-11222, CVE-2026-12910, CVE-2026-82837, CVE-2026-19619, CVE-2026-86341, CVE-2026-86340, CVE-2026-7514, CVE-2026-8030, CVE-2026-16794, CVE-2026-3855, Summary: On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE)…

CVSS 10.0 GitLab FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

1

SPOJENO PŘES CVE Risolte vulnerabilità in GitLab CE/EE

Aggiornamenti di sicurezza rilasciati per GitLab, nota piattaforma per la gestione del ciclo di sviluppo software e della collaborazione sui progetti, sanano alcune vulnerabilità, di cui 2 con gravità "critica" e 6 con gravità "alta"

KEV ✓ EPSS 0.15 CVSS 10.0 CVE-2025-14871 CVE-2026-1168 CVE-2026-13210 CVE-2026-78252 CVE-2026-79708 CVE-2026-85706 CVE-2026-87719 CVE-2026-88765 GitLab IT US

tg: zranitelnost tg: novinka v produktu

· CSIRT Itálie (ACN) · Risolte vulnerabilità in GitLab CE/EE · GitLab Security · GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

1

CI/CD pipeline abuse: the problem no one is watching

Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…

GitHub GitLab Microsoft US

tg: rozbor tg: novinka v produktu tp: dodavatelský řetězec tp: AI tp: identita

· Elastic Security · CI/CD pipeline abuse: the problem no one is watching