❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

GitLab’s critical flaw is already drawing internet-wide probes

By: Greg Otto
11 September 2026 at 14:41

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws.

The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted.

The more serious of the two flaws, tracked as CVE-2026-85706, sits in the interface that handles repository commits. GitLab said that under certain conditions an attacker could read any file on the server, because the code failed to confine file paths properly and did not enforce authentication. An attacker does not need an account nor credentials to take advantage of the flaw.

The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches. GitLab assigned it a CVSS score of 10.0, the top of the scale used across the industry.

The second flaw, CVE-2026-87719, affects only GitLab’s Enterprise Edition. The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature, which would return the settings and passwords being held. It affects releases from 18.3 onward and carries a CVSS score of 9.9. 

WatchTowr Labs wrote in a LinkedIn post Friday that it was already watching probes against the path traversal flaw, which it said an attacker can trigger in one HTTP request. The firm said organizations running self-hosted GitLab servers reachable from the open internet face the greatest risk, and pointed defenders toward their logs, suggesting they look for POST requests to addresses under /api/v4/projects/{id}/repository/commits/ that carry a file.path parameter. 

Drawing on earlier GitLab flaws, the firm said broad, untargeted attacks tend to follow soon after a patch appears.

“Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” the post read. 

The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) list on Friday afternoon. 

You can find more information about the vulnerabilities on GitLab’s website. 

Update: Sept. 11, 2026; 4:30 p.m.: This story has been updated to reflect the vulnerability being added to CISA’s KEV list.

The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop.

Attackers exploit zero-days in consistently besieged SonicWall product

3 September 2026 at 18:12

SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. 

The vendor disclosed and released patches for the defects — CVE-2026-83548 and CVE-2026-83549 — and noted both were already actively exploited in the wild in a security advisory Tuesday. The Cybersecurity and Infrastructure Security Agency added the defects to its known exploited vulnerabilities (KEV) catalog Wednesday. 

SonicWall customers have confronted a barrage of actively exploited vulnerabilities in SonicWall devices for years. Attackers have consistently exploited newly discovered zero-days and years-old defects in the vendor’s products to break into victim environments.

Rapid7 researchers said the new zero-days — a max-severity pre-authentication server-side request forgery vulnerability and a high-severity OS command injection vulnerability — can be chained together to achieve unauthenticated remote-code execution. 

SonicWall did not say how many customers have been directly impacted by active exploitation or when the first known instance of exploitation occurred. The company did not respond to a request for comment.

“Please stop us if you’ve heard this one before: Another appliance sitting at the edge of the network, another pair of vulnerabilities chained together, and another unauthenticated path to complete compromise,” Jake Knott, head of threat intelligence at watchTowr, said in an email. 

“SonicWall says these vulnerabilities were internally discovered, while also saying it investigated a case indicating active exploitation. Please pick one, or, at minimum, explain how both are true,” Knott added. “Those statements may be technically accurate, but without that context, the disclosure leaves defenders guessing about when and how the vulnerabilities were actually identified.”

The vendor’s security advisory did not include indicators of compromise. It urged customers to contact tech support for assistance in reviewing IOCs and hunting for potential signs of compromise, and if detected, to reimage or redeploy the appliance, change all user and administrator passwords and reset tokens. 

SonicWall did not attribute the known exploits to a specific threat group or describe the attacker’s motivations.

The freshly disclosed pair of vulnerabilities are the latest in a series of security issues confronting the vendor’s customers, including actively exploited zero-days, previously disclosed defects, and an attack last year that allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer. 

In late July, Huntress researchers spotted an attack spree that compromised 30 SonicWall customers in less than two days. Earlier that month, the company acknowledged another pair of zero-days that were exploited for three weeks before the vendor disclosed and patched the defects.

Ransomware groups, including INC ransomware and Akira, have taken a special interest in SonicWall. Ten of the 19 SonicWall defects added to CISA’s KEV catalog since late 2021 are known to be used in ransomware campaigns.

The five defects added to CISA’s KEV most recently, since just mid-December 2025, all impact SonicWall SMA 1000 appliances.

The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop.

SonicWall customers under threat as attackers exploit 2 zero-days

15 July 2026 at 14:51

SonicWall customers are attempting to dodge another security challenge as attackers are exploiting a pair of zero-day vulnerabilities that have been confirmed by the vendor. 

The company publicly disclosed the vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — in a security advisory Tuesday. SonicWall credited an employee with discovering the defects, but it hasn’t said when the discovery occurred or the earliest known instance of exploitation. 

Rapid7 researchers told CyberScoop both vulnerabilities were first exploited June 22. “From the cases that our team has observed, the goal is likely ransomware, though we have prevented the actors from achieving exfiltration and encryption,” said Seth Lazarus, senior manager of detection and response services at Rapid7.

Overlapping tactics, techniques and procedures from the attacks observed by Rapid7 indicate the same threat group or attacker discovered and exploited the zero-days, Lazarus added.

SonicWall did not answer questions about the impacts of these attacks thus far, and the company hasn’t attributed the attacks to a known group or described the attacker’s origins and motivations.

The vendor did, however, confirm to CyberScoop that both vulnerabilities have been chained together for exploitation. The vulnerabilities affecting SonicWall SMA1000 appliances, including a max-severity defect that allows attackers to make authenticated requests and a 7.2-rated vulnerability that allows authenticated command injection.

“When these two are chained, an attacker can go from zero access to a complete system compromise for the affected appliance,” said Landon Rice, senior exploit developer at VulnCheck.

Ben Harris, founder and CEO at watchTowr, said two characteristics of the vulnerabilities fuel a sense of dread. “Both were exploited as zero-days before fixes were available, and together they offer a plausible path to remote-code execution from the internet,” he said.

The Cybersecurity and Infrastructure Security Agency added both zero-days to its known exploited vulnerabilities catalog Tuesday. 

SonicWall encouraged customers to patch the vulnerabilities by upgrading to the latest software version, which it released upon disclosure, and shared some indicators of compromise to help customers hunt for potential malicious activity on their systems.

“Speed of response was a priority for us,” said Bret Fitzgerald, senior director of global communications at SonicWall. “Within days of becoming aware of the issue, our team had developed a script that we can run on behalf of affected customers to assist with resolution, and mitigation efforts are already underway.”

SonicWall and third-party researchers haven’t said how many SonicWall customers are impacted by the exploited vulnerabilities, but the vendor did say it already investigated multiple cases of active exploitation. 

Fitzgerald said the company monitors about one million sensors globally and “SMA1000 appliances represent a very small subset of that footprint, less than 5,000 units.”

SonicWall said support staff are also helping customers work through instances of suspicious activity, warning that patching alone is not sufficient. 

The vendor and its customers have been hit by a barrage of actively exploited zero-days and previously disclosed defects in SonicWall devices for years. In 2025, an undisclosed state-sponsored threat actor intruded the company’s cloud environment and stole firewall configurations of every SonicWall customer. 

Seventeen defects affecting the vendor’s products have been added to CISA’s known exploited vulnerabilities catalog since late 2021. Ten of those defects are known to be used in ransomware campaigns, according to CISA, including a wave of about 40 Akira ransomware attacks between mid-July and early August.

“As always,” Harris said, “when something is confirmed as already exploited in the wild, patching is the bare minimum, and breach should be assumed.”

The post SonicWall customers under threat as attackers exploit 2 zero-days appeared first on CyberScoop.

❌
❌