Skip to content

CVE-2021-39935

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
February 4, 2026
Last Seen
September 11, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization....

CISA has added a critical server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise editions, tracked as CVE-2021-39935, to its Known Exploited Vulnerabilities catalog. This vulnerability is currently being exploited by threat actors, posing risks to organizations using aff...

Public Exploits

Checking GitHub for proof-of-concept code…