GitLab Issues Urgent Patches for CVE-2026-85706 as In-the-Wild Exploits Emerge

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

GitLab has released patches to address multiple flaws, including a critical security vulnerability that has already been exploited in the wild. The vulnerability, identified as CVE-2026-85706 with a CVSS score of 10.0, is a path traversal issue in the repository commits API, allowing unauthenticated users to read arbitrary files from the GitLab server under certain conditions.

The issue arises from “improper path confinement and missing authentication enforcement in the repository commits API,” according to GitLab. It affects all versions of GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2.

As reported by the exposure management firm watchTowr, active probes exploiting this vulnerability began as early as 06:00 UTC on September 11, 2026. The flaw enables external attackers to access log files and GitLab-specific configuration files, potentially exposing credentials and sensitive information.

This incident marks the second critical vulnerability in GitLab within a short period, following the GraphQL code injection vulnerability CVE-2026-19478, which was also quickly exploited. Jake Knott, head of threat intelligence at watchTowr, noted that exploitation requires at least one public project to exist.

Additionally, GitLab has patched a critical insecure deserialization bug (CVE-2026-87719, CVSS score: 9.9) that could lead to information disclosure. This vulnerability allows authenticated users with Duo Chat access to obtain sensitive configurations and credentials through specially crafted GraphQL subscription arguments.

Organizations operating self-managed GitLab instances exposed to the internet are urged to apply the patches immediately or restrict public access if not necessary. “The transition of this vulnerability to mass exploitation is likely imminent, and defenders have limited time to act,” Knott warned.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Ukrainian National Sentenced to Four Years for Role in Conti Ransomware Attacks

A 44-year-old Ukrainian national has been sentenced to four years in prison for his involvement in the Conti ransomware group, which targeted over 1,000...

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...