GitLab security advisory (AV26-917)
As of September 10, 2026, GitLab is affected by vulnerabilities in the following product:
- GitLab
- Prior to 19.1.8
- Prior to 19.2.6
- Prior to 19.3.2
On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
At a glance
- Severity
- Mediumfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- GitLab
- Threat actors & malware
- None named
- Industries
- Government
- Coverage
- 1 outlet· first seen 2026-09-11 20:35 UTC
- Priority
- 49/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-11 20:35 UTC
Related stories
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The Hacker News · 2026-09-12
- n8n security advisory (AV26-916)
Canadian Centre for Cyber Security · 2026-09-11
- Progress security advisory (AV26-915)
Canadian Centre for Cyber Security · 2026-09-11
- CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
Dark Reading · 2026-09-11
- GitLab’s critical flaw is already drawing internet-wide probes
CyberScoop · 2026-09-11