TODAY
GitLab and Cisco firewall auth bypasses under active attack — patch now.
THE THREE
- KEV#1 · CVE-2026-85706
Gitlab
What: Any unauthenticated attacker on the internet can read arbitrary files from your GitLab server — including source code, secrets, and credentials — without logging in. With a 93% exploit probability and active exploitation confirmed, this is a high-priority target for data theft and supply chain attacks.
Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Update GitLab CE/EE to the latest patched version immediately.
- KEV#2 · CVE-2026-20079
Cisco
What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, meaning your firewall policy and network defenses could be read or altered by anyone on the internet. This is a full perimeter compromise risk.
Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Cisco's patch for FMC/SCC and restrict management interface access to trusted IPs.
- KEV#3 · CVE-2026-81578
Papercut
What: PaperCut NG/MF print management servers — common in schools, hospitals, and offices — can be reconfigured by unauthenticated remote attackers, and this flaw chains with a second vulnerability for deeper compromise. Ransomware groups have historically targeted PaperCut heavily.
Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch PaperCut NG/MF to the latest version and block external access to the admin port.
TRAVERSAL
No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.
NUMBERS
- Entities
- 12M
- Relationships
- 67M
- Threat actors
- 242
- Indicators
- 961k
- Feeds live
- 20
- Sources total
- 24
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.