TODAY
GitLab and Cisco Firewall auth bypasses under active attack — patch now.
THE THREE
- KEV#1 · CVE-2026-85706
Gitlab
What: Any unauthenticated attacker on the internet can read arbitrary files from your GitLab server — including source code, secrets, and credentials — without logging in. With a 93% exploit probability and CVSS 10.0, this is as dangerous as it gets for dev teams hosting code internally or in the cloud.
Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update GitLab CE/EE to the latest patched version immediately.
- KEV#2 · CVE-2026-20079
Cisco
What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, potentially taking over your firewall policy and opening your network to intrusion. This is a CVSS 10.0 flaw being actively exploited against a product that sits at the heart of many organizations' security perimeter.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Cisco's patch for FMC/SCC and verify no unauthorized admin sessions exist.
- KEV#3 · CVE-2026-81578
Papercut
What: PaperCut NG/MF — common in schools, universities, and offices — lets an unauthenticated remote attacker change system configurations, and this flaw chains with CVE-2026-82078 for full server compromise. Ransomware groups have historically targeted PaperCut heavily.
Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch PaperCut NG/MF now and block external access to the admin web interface.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 12M
- Relationships
- 67M
- Threat actors
- 239
- Indicators
- 930k
- Feeds live
- 19
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.