The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are actively exploiting a maximum-severity GitLab vulnerability tracked as CVE-2026-85706. The flaw stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated attackers to read credentials, secrets, and other sensitive files from