Malicious actors already using critical GitLab flaw, CISA and others warn

MediumCybersecurity Dive · Eric Geller·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
GitLab
Industries
Government
Reported by
1 outlet

An article from

The vulnerability could let unauthenticated users access sensitive files from software-development environments.

Published Sept. 14, 2026

Hackers have begun exploiting a serious vulnerability in a popular software development tool, the Cybersecurity and Infrastructure Security Agency is warning.

CISA on Friday listed the vulnerability in GitLab’s development platform in its Known Exploited Vulnerabilities catalog, giving federal agencies until Monday to mitigate the risks associated with the flaw.

The vulnerability, tracked as CVE-2026-85706, involves a lack of authentication requirements and a lack of restrictions on where users can place files. Malicious actors could exploit the flaw to access files on GitLab servers without authorization. GitLab released a patch for the flaw on Sept. 10.

In issuing a CVE for the vulnerability, GitLab assigned it the maximum score of 10, indicating a critical flaw that organizations should patch as soon as possible. But for some organizations, it is already too late.

The cybersecurity firm watchTowr said on Friday that its intelligence analysts were “already observing in-the-wild probes” for servers running vulnerable versions of GitLab. The firm warned that hackers could use the flaw to “read local files and configs to obtain credentials, secrets, and sensitive information.”

“Based on recent GitLab vulnerabilities,” watchTowr added, “we know the time until indiscriminate exploitation is likely not far away.”

Hong Kong’s computer emergency response team released an advisory about the flaw on Monday, warning that it was “being exploited in the wild.”

In its security update on Thursday, GitLab also patched a second vulnerability, CVE-2026-87719, which could have allowed attackers to obtain sensitive information from servers running GitLab’s enterprise edition.

The new vulnerabilities are the latest major security weaknesses in GitLab’s products. The company disclosed CVE-2025-0376 in early 2025, as well as three more — CVE-2026-1092, CVE-2025-12664 and CVE-2026-5173 — in April. GitLab disclosed another critical flaw, CVE-2026-19478, in August, prompting hackers to begin exploiting it within days.

Reproduced in full under licence from Cybersecurity Dive. © Cybersecurity Dive. Written by Eric Geller.

Coverage

One outlet has carried this so far.

  1. Cybersecurity DiveEstablished SourceFirst reported

    2026-09-14 14:46 UTC

Related stories