Summary
CISA has added a critical GitLab path traversal vulnerability (CVE-2026-85706) to its Known Exploited Vulnerabilities catalog, urging immediate patching as it is being actively exploited. The flaw allows unauthenticated attackers to read sensitive files via the repository commits API, and government agencies have been given three days to update to patched versions.