TODAY
GitLab and Cisco firewall auth bypasses actively exploited — patch now.
THE THREE
- KEV#1 · CVE-2026-85706
Gitlab
What: Any organization running GitLab (self-hosted) is at risk — an unauthenticated attacker can read any file on your GitLab server through the API, including secrets, credentials, and source code, with no login required. This is a perfect 10.0 CVSS and is actively being exploited right now.
Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update GitLab CE/EE to the latest patched version immediately.
- KEV#2 · CVE-2026-20079
Cisco
What: If your organization uses Cisco Firewall Management Center or Cisco Security Cloud Control to manage your firewalls, an attacker on the internet can bypass authentication entirely and take control — effectively owning your firewall policy without a password. This is a perfect 10.0 CVSS and actively exploited.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Cisco's patch for FMC/SCC and restrict management interface access to trusted IPs.
- KEV#3 · CVE-2026-81578
Papercut
What: Organizations using PaperCut NG or MF for print management are exposed — an unauthenticated attacker can remotely change system configurations, and chaining this with CVE-2026-82078 (below) leads to full server compromise. PaperCut is common in schools, healthcare, and offices.
Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch PaperCut NG/MF to the latest version and block external access to the admin port.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 12M
- Relationships
- 67M
- Threat actors
- 242
- Indicators
- 940k
- Feeds live
- 19
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.