AI-Generated · google/gemini-2.5-flash-lite via openrouter/openrouter/auto-beta; researched by moonshotai/kimi-k2-0905

CISA Adds Max-Severity GitLab Flaw to Exploited Vulnerabilities List

CISA has added a critical GitLab vulnerability to its Known Exploited Vulnerabilities catalog following active exploitation in the wild.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE) to its Known Exploited Vulnerabilities (KEV) catalog. This move came on September 11, 2026, following the detection of active exploitation in the wild just one day after GitLab released a patch for the issue as reported by Bleeping Computer.

The vulnerability, identified as CVE-2026-85706, carries a maximum severity score of CVSS 10.0. It is a path traversal flaw that allows unauthenticated attackers to read arbitrary files. This could include sensitive information such as credentials and secrets, accessible through a single HTTP POST request directed at the repository commits API according to Infosecurity Magazine.

GitLab addressed the vulnerability by releasing patches on September 10, 2026. The affected versions include GitLab CE/EE versions 18.7 before 19.1.8, versions 19.2 before 19.2.6, and versions 19.3 before 19.3.2 as detailed by Infosecurity Magazine.

CISA’s inclusion of CVE-2026-85706 in its KEV catalog mandates federal agencies to remediate the vulnerability within three days, setting a deadline of September 15, 2026 as stated by Bleeping Computer.

In-the-wild probes for this vulnerability were observed on September 11, 2026, by WatchTowr Intel. This rapid detection and exploitation following the patch release suggests a significant risk to organizations running vulnerable instances of GitLab according to Bleeping Computer.

WatchTowr Intel has warned that indiscriminate exploitation of this vulnerability is likely imminent, drawing parallels to patterns observed with previous GitLab security flaws. The ease with which attackers can exploit this path traversal vulnerability, allowing them to read sensitive files with minimal effort, makes it a prime target for malicious actors as noted by Infosecurity Magazine.

Directory traversal attacks, also known as path traversal, are a class of security exploit where an attacker manipulates an application’s input to access files and directories outside of the web root folder. Exploiting CVE-2026-85706 allows attackers to bypass access controls and retrieve sensitive data, posing a severe risk to system integrity and data confidentiality learn more about directory traversal attacks.

Organizations using GitLab CE/EE are strongly advised to apply the available patches immediately to mitigate the risk of exploitation. The swift action by CISA underscores the critical nature of this vulnerability and the immediate threat it poses to systems worldwide.

Sources