Defendwork Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches
Article Content
- •GitLab CVE-2026-85706 exploited within hours of disclosure.
- •Microsoft's patch update addresses 974 vulnerabilities, a record number.
- •Anthropic disrupted state-sponsored cyber-espionage campaigns linked to Russia.
A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows unauthenticated attackers to read arbitrary files from affected servers, posing a significant risk to users of GitLab Community and Enterprise Editions. Additionally, Anthropic disrupted state-sponsored cyber-espionage campaigns linked to Russia, targeting over 20 government entities, and identified industrial-scale attacks from Chinese labs using AI for malicious purposes. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, 2026, with a federal remediation deadline set for September 14, 2026. Organizations are advised to apply patches immediately and monitor for unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Gtg-20006, ConnectWise and CVE-2026-42016 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Critical CSF Vulnerability Allows Remote Code Execution A critical vulnerability in ConfigServer Security & Firewall (CSF), tracked as CVE-2026-65638, was disclosed on September 10, 2026. This flaw affects CSF versions 14.00 through 16.29, allowing unauthenticated remote attackers to execute arbitrary commands via the MESSENGER service. Administrators are urged to upgrade…