GitLab has released patches to address multiple flaws, including a critical security vulnerability that has already been exploited in the wild. The vulnerability, identified as CVE-2026-85706 with a CVSS score of 10.0, is a path traversal issue in the repository commits API, allowing unauthenticated users to read arbitrary files from the GitLab server under certain conditions.
The issue arises from “improper path confinement and missing authentication enforcement in the repository commits API,” according to GitLab. It affects all versions of GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2.
As reported by the exposure management firm watchTowr, active probes exploiting this vulnerability began as early as 06:00 UTC on September 11, 2026. The flaw enables external attackers to access log files and GitLab-specific configuration files, potentially exposing credentials and sensitive information.
This incident marks the second critical vulnerability in GitLab within a short period, following the GraphQL code injection vulnerability CVE-2026-19478, which was also quickly exploited. Jake Knott, head of threat intelligence at watchTowr, noted that exploitation requires at least one public project to exist.
Additionally, GitLab has patched a critical insecure deserialization bug (CVE-2026-87719, CVSS score: 9.9) that could lead to information disclosure. This vulnerability allows authenticated users with Duo Chat access to obtain sensitive configurations and credentials through specially crafted GraphQL subscription arguments.
Organizations operating self-managed GitLab instances exposed to the internet are urged to apply the patches immediately or restrict public access if not necessary. “The transition of this vulnerability to mass exploitation is likely imminent, and defenders have limited time to act,” Knott warned.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



