Tag: unauthenticated

Week 38 – GitLab Under Attack: Critical Arbitrary File Read Vulnerability

14 – 20 Sept 2026 What if an unauthenticated user could read your sensitive data from the GitLab server? This week’s CVE of the Week highlights CVE-2026-85706 in GitLab – a critical CVSS 10.0 flaw that could allow unauthenticated attackers to read arbitrary files from …

Week 34 – From Auto-Login to Full RCE: Inside the IBM Langflow CVE

17 – 23 Aug 2026 AI platforms are increasingly becoming attractive targets for attackers. CVE-2026-9198 affects IBM Langflow OSS and chains security flaws that can lead to unauthenticated Remote Code Execution (RCE). With public PoCs available and the vulnerability already exploited in the wild, affected …