Critical GitLab vulnerability allows unauthenticated data exfiltration and is already under attack
CVE-2026-85706 has the maximum severity score (CVSS 10.0) and allows anyone, without logging in, to read arbitrary files from self-managed GitLab instances. The fix has existed since September, but CISA confirms active exploitation.





