GitLab Path Traversal Vulnerability: Patch Now

A critical GitLab path traversal vulnerability lets attackers read any file from self-managed servers with no login. Active exploitation confirmed.

A critical GitLab path traversal vulnerability, CVE-2026-85706 (CVSS 10.0), lets an unauthenticated attacker read any file off a self-managed GitLab server, including credentials, deploy keys, and CI/CD configuration. GitLab shipped a patch on September 10; CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, and BSI issued its own warning on…

Read More

Top 5 Cybersecurity News

Top 5 Cybersecurity News, September 18, 2026: Cisco ISE, ScreenConnect, GitLab and Pixel zero-days, plus the EU's new CRA reporting duty.

This week’s Top 5 Cybersecurity News keeps returning to the same uncomfortable pattern: the systems under attack are not the ones organizations watch closely, they’re the ones organizations trust by default. Identity platforms, remote-support tools, developer infrastructure, and mobile devices all exist specifically so that legitimate work can move faster and with less friction. This…

Read More

LiteLLM MCP Authentication Bypass: Patch Now

A LiteLLM MCP authentication bypass lets attackers skip OAuth2 login entirely. Active exploitation confirmed, first MCP flaw in CISA KEV.

A LiteLLM MCP authentication bypass, CVE-2026-59822 (CVSS 8.8), lets an attacker skip OAuth2 login entirely when connecting to Model Context Protocol servers through LiteLLM’s proxy, gaining whatever access an authenticated session would carry. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, the first MCP-related vulnerability ever listed there; WatchTowr reports…

Read More

Cisco Secure Email Gateway Vulnerability: Patch Now

A critical Cisco Secure Email Gateway vulnerability lets one crafted email grant root access, no login needed. Active exploitation confirmed.

A critical Cisco Secure Email Gateway vulnerability, CVE-2026-76461 (CVSS 9.8), lets an attacker gain root access to the appliance by sending a single crafted email, no login or admin access required. Cisco confirmed active exploitation and published its advisory September 14; CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and…

Read More

N-able N-central RCE Vulnerability Hit Again

N-able N-central RCE Vulnerability Hit Again

An N-able N-central RCE vulnerability has forced the vendor to ship its fourth emergency hotfix in five weeks, and Huntress investigators say a customer’s server — already patched against an earlier round of flaws — was compromised a second time anyway. Tracked as CVE-2026-86218 with a maximum CVSS score of 10.0, the flaw hits a…

Read More