ThreatsTechnology, Cloud & SaaSBreakingGitLab fixes maximum-severity CVSS 10.0 file-read flaw as in-the-wild exploitation beginsGitLab pushed emergency patches for CVE-2026-85706, an unauthenticated CVSS 10.0 path traversal flaw in the repository commits API that allows remote file extraction.Priya Raman·12 Sep 2026, 13:30 IST·6 min read