TODAY
Two perfect-10 CVEs actively exploited; patch GitLab and Cisco FMC now.
THE THREE
- KEV#1 · CVE-2026-85706
Gitlab
What: Any organization running GitLab (self-hosted or otherwise) is exposed — an unauthenticated attacker can read any file on your GitLab server through the API, meaning source code, secrets, and credentials are at risk with no login required. With a 91% exploit probability and active exploitation confirmed, this is the top priority today.
Why it moved: Actively exploited · Widely deployed · Critical severity · 91% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply GitLab's latest security patch immediately across all CE and EE instances.
- KEV#2 · CVE-2026-20079
Cisco
What: If your organization uses Cisco Firewall Management Center or Cisco Security Cloud Control to manage your firewalls, an attacker on the internet can bypass authentication entirely and take control — effectively owning your firewall management plane without a password. This is a complete perimeter security failure.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Cisco FMC and SCC to the vendor-fixed version right now, no exceptions.
- KEV#3 · CVE-2026-8037
Progress
What: Progress LoadMaster is a load balancer used in many data centers; this flaw lets an unauthenticated attacker run any command on the appliance, potentially pivoting deep into your internal network. It has been actively exploited for nearly two months.
Why it moved: Actively exploited · Widely deployed · Critical severity · 77% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update Progress LoadMaster firmware to the patched release immediately.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 12M
- Relationships
- 67M
- Threat actors
- 239
- Indicators
- 925k
- Feeds live
- 19
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.