<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Security Vulnerabilities</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Security Vulnerabilities feed</description>
    <item>
      <title>GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration</title>
      <link>https://www.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/en/headerimage/gitlab-cloud-seed-preview-1791042234130.jpeg"/&gt;&lt;p&gt;CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Continuous Deployment</category>
      <category>Security Vulnerabilities</category>
      <category>Software Supply Chain</category>
      <category>Continuous Integration</category>
      <category>GitLab</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Sat, 03 Oct 2026 16:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-10-03T16:00:00Z</dc:date>
      <dc:identifier>/news/2026/10/gitlab-critical-vulnerabilities/en</dc:identifier>
    </item>
    <item>
      <title>Artifactory Vulnerabilities under Active Exploitation Enable Authentication Bypass and Admin Access</title>
      <link>https://www.infoq.com/news/2026/09/artifactory-vulnerabilities/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/artifactory-vulnerabilities/en/headerimage/secretflow-privacy-preserving-1790621168767.jpg"/&gt;&lt;p&gt;Three Artifactory vulnerabilities under active exploitation enable authentication bypassing on Internet-accessible, self-hosted deployments, potentially allowing attackers to establish persistent administrator access in under five minutes. The exploits then enable dangerous activity, including credential and key theft, arbitrary code execution, persistence, and anti-forensics measures.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Security Vulnerabilities</category>
      <category>Software Supply Chain</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Mon, 28 Sep 2026 19:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/artifactory-vulnerabilities/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Security+Vulnerabilities</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-09-28T19:00:00Z</dc:date>
      <dc:identifier>/news/2026/09/artifactory-vulnerabilities/en</dc:identifier>
    </item>
  </channel>
</rss>
