
GitLab CVE-2026-85706 Path Traversal: Emergency Patch
GitLab CVE-2026-85706 CVSS 10.0 path traversal lets unauthenticated attackers read any server file -- SSH keys, CI/CD tokens, deploy credentials. CISA deadline is today. Patch to 19.3.2 now.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
12 results in ZERO-DAY

GitLab CVE-2026-85706 CVSS 10.0 path traversal lets unauthenticated attackers read any server file -- SSH keys, CI/CD tokens, deploy credentials. CISA deadline is today. Patch to 19.3.2 now.

MikroTrick SSH auth bypass CVE-2026-67276 chains with CVE-2026-86060 for unauthenticated root on 122,500 RouterOS devices. CISA KEV confirmed. Patch to 7.24.2 now.

CVE-2026-20079 in Cisco FMC lets attackers get root without credentials. Sandworm and Qilin are already inside. Patch to FMC 7.0.0 before Sept 12.

CVE-2026-75650 StyleSmuggler hit Adobe Commerce 2.4.4-2.4.9 with no-auth RCE 3 days before any patch. Apply VULN-39341 and rotate all credentials now.

CVE-2026-86218 is a CVSS 10.0 pre-auth RCE in N-able N-central. Patch to build 2026.3.1.14 now. Third attack wave in six weeks targets ~1,500 exposed MSP servers.

CVE-2026-19490 Citrix NetScaler auth bypass is under active exploitation with 22,000+ exposed gateways. Patch to 14.1-73.32 now. The prior CVE-2026-8452 hotfix is insufficient.

SonicWall SMA1000 zero-day CVE-2026-83548 chains SSRF with command injection for unauthenticated RCE on 400+ exposed appliances. Apply hotfix now.

CVE-2026-62911 PoC chains NTLM relay to Exchange MRSProxy to drop ASPX webshells as SYSTEM. Apply August 2026 update before mass exploitation begins.

ServiceNow CVE-2026-18885 unauthenticated RCE: three CVSS 10.0 flaws enable GraphQL injection, privilege escalation, and SQL injection. Patch self-hosted Xanadu, Yokohama, and Zurich now.

CVE-2026-8452 Citrix NetScaler SAML RCE: pre-auth heap overflow exploited in 24 hours after PoC. Webshells x.php and z.php active. CISA KEV deadline is today. Patch to 14.1-73.32 now.

Zimbra CVE-2026-73570 SNMP command injection has compromised 274 servers with 8,200 more at risk. CISA KEV added August 21 with 3-day deadline. Patch to ZCS 10.1.20 now.

MLflow SSRF CVE-2026-64849 lets attackers steal cloud IAM credentials without authentication. CISA KEV added Aug 19; federal deadline Sep 2. Patch to 3.15.0 now.