GitLab's Critical File-Read Flaw Shows Why Patching Is Only the First Incident-Response Step
GitLab patched CVE-2026-85706 on September 10 and CISA added it to the Known Exploited Vulnerabilities catalog on September 11. The newer operational signal is GitLab's guidance for checking whether suspicious requests actually disclosed file contents.
2026-09-19