TODAY
GitLab and Cisco firewall auth bypasses under active attack — patch now.
THE THREE
- KEV#1 · CVE-2026-85706
Gitlab
What: Any unauthenticated attacker can read arbitrary files from your GitLab server — including source code, secrets, and credentials — without logging in at all. With a 93% exploit probability and active exploitation confirmed, exposed GitLab instances are being hit right now.
Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply GitLab's latest security patch or block unauthenticated access to the repository commits API immediately.
- KEV#2 · CVE-2026-20079
Cisco
What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, meaning your firewall policies and network controls could be altered or read by anyone on the internet. This is a perfect entry point for ransomware or espionage.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Cisco FMC and SCC to the vendor-fixed version or restrict management interface access to trusted IPs only.
- KEV#3 · CVE-2026-81578
Papercut
What: An unauthenticated attacker can change system configurations on your PaperCut print management server, and when chained with CVE-2026-82078 (also listed today), this leads to full remote code execution. PaperCut is common in schools, offices, and healthcare.
Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update PaperCut NG/MF to the patched version and restrict server access to internal networks only.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 12M
- Relationships
- 67M
- Threat actors
- 242
- Indicators
- 944k
- Feeds live
- 19
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.