PT-2026-89811 · Gitlab · Gitlab

CVE-2026-85706

·

Published

2026-09-11

·

Updated

2026-09-12

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
𝗧𝗵𝗲 𝗗𝗮𝗶𝗹𝘆 𝗧𝗿𝗮𝗰𝗲 | September 12, 2026 Your Daily Crypto News Digest
𝗧𝗼𝗽 𝗦𝘁𝗼𝗿𝘆 An attacker reportedly bridged 257.7M NES, roughly $50M, from Nesa to Ethereum in a move consistent with a bug chain also affecting MANTRA Chain, TacBuild, and KiiChainio; Nesa never published the mechanism, and net profit was put at $60k after slippage. (via @RektHQ)
𝗛𝗮𝗰𝗸𝘀 & 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝘀
  • Blockstream said it will not pay a ransom for return of $47M in bitcoin from a Liquid hack, calling it theft, and warned it will go to law enforcement if the 598.5 BTC outstanding is not returned. (via @decryptmedia)
  • The Florida Department of Motor Vehicles confirmed a data breach claimed by ShinyHunters, saying it originated with credentials stolen from a police officer's personal device. (via @TheRecord Media)
  • SlowMist reported an ORB token loss of approximately $32,610.72, attributing it to a missing reentrancy guard in the ORBToken contract that enabled tax-free sell-offs and reserve manipulation. (via @SlowMist Team)
𝗘𝗻𝗳𝗼𝗿𝗰𝗲𝗺𝗲𝗻𝘁, 𝗔𝗿𝗿𝗲𝘀𝘁𝘀 & 𝗦𝗲𝗶𝘇𝘂𝗿𝗲𝘀
  • An operation coordinated by German and Italian authorities executed six arrest warrants and searched 16 properties across Germany, Italy, and Spain, seizing counterfeit euro banknotes, two pistols, and 16 mobile phones and storage devices. (via @Europol)
  • Europol supported a separate operation against a network suspected of trafficking horses across Europe using falsified documents and manipulated microchips to conceal the animals' identities. (via @Europol)
𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 & 𝗠𝗮𝗹𝘄𝗮𝗿𝗲
  • Threat actors began exploiting CVE-2026-85706, a critical path traversal flaw in self-hosted GitLab instances, just one day after GitLab disclosed and patched it on September 10; watchTowr warns mass exploitation is likely. (via @DarkWebInformer)
  • Revolut exposed customer passports, selfies, home addresses, and bitcoin activity after treating a fraudulent government request as legitimate; no customer funds were lost. (via @CoinDesk)
  • A SmartLoader campaign distributes malware through typosquatted GitHub repositories and uses ETH smart contracts and the Prometheus obfuscator for command-and-control. (via @vxunderground)
Follow BlockchainUnmasked for your daily news digest every morning

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85706

Affected Products

Gitlab