TODAY
GitLab and Cisco firewall auth bypasses under active attack — patch now.
THE THREE
- KEV#1 · CVE-2026-85706
Gitlab
What: Any unauthenticated attacker on the internet can read arbitrary files from your GitLab server — including source code, secrets, and credentials — without logging in. With a 91% exploit probability and active exploitation confirmed, this is being hit right now.
Why it moved: Actively exploited · Widely deployed · Critical severity · 91% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch GitLab CE/EE to the vendor-fixed version immediately.
- KEV#2 · CVE-2026-20079
Cisco
What: Attackers can completely bypass login on Cisco Firewall Management Center and Security Cloud Control, potentially taking over your firewall policy and opening your network to anything they want. This is as bad as it gets for perimeter security.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Cisco's patch for FMC/SCC and verify no unauthorized admin sessions exist.
- KEV#3 · CVE-2026-81578
Papercut
What: PaperCut NG/MF — used in offices and schools everywhere for print management — lets an unauthenticated remote attacker change system configurations, and this flaw chains with CVE-2026-82078 for full compromise. Ransomware groups have historically loved PaperCut.
Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update PaperCut NG/MF and restrict the admin web interface to internal IPs only.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 12M
- Relationships
- 67M
- Threat actors
- 239
- Indicators
- 927k
- Feeds live
- 19
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.