Security news
Latest security news
Mon, 14 Sept 2026
- Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
CriticalUsed in attacksDark ReadingGitLab - Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments.
Cybersecurity DiveGitLab - Perfect-10 GitLab bug under attack days after patch lands
CISA confirms active exploitation as watchTowr spots miscreants probing internet-facing servers
The RegisterGitLab - CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04. Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles. Mitigation guidance A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected self-mana
CriticalUsed in attacksRapid7 BlogGitLab - Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
Infosecurity MagazineGitLab - CISA: Hackers now exploit max severity GitLab flaw in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
BleepingComputerGitLab
Fri, 11 Sept 2026
- GitLab security advisory (AV26-917)
Serial Number: AV26-917 Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 | GitLab Docs GitLab release notes | GitLab Docs CISA KEV: CVE-2026-85706
Canadian Centre for Cyber SecurityGitLab - GitLab’s critical flaw is already drawing internet-wide probes
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately.
CyberScoopGitLab - GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
The Hacker NewsGitLab - GitLab Vulnerability Exploited One Day After Disclosure
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
SecurityWeekGitLab
About this news
- 1,256
- Stories
- 41
- Added in the last 24 hours
- 19
- Critical in the last 7 days
- 4
- Reported by several outlets