GitLab released patches for CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API allowing unauthenticated users to read arbitrary files. The vulnerability has already been probed in-the-wild within hours of disclosure, affecting multiple GitLab Community and Enterprise Edition versions. A second critical flaw, CVE-2026-87719, an insecure deserialization bug in GitLab EE, was also patched.