Government Advisory

Actively Exploited GitLab Vulnerability Added to US Government Threat List

CISA · 11 Sept 2026
Key Takeaway If your business uses GitLab Community or Enterprise Edition, check your version and apply the latest security patch immediately, as this vulnerability is already being actively exploited.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-85706, to its Known Exploited Vulnerabilities Catalog. The vulnerability affects GitLab Community Edition and Enterprise Edition and is classified as a path traversal issue, a type of bug that allows attackers to access files or areas of a system they shouldn't be able to reach. CISA confirmed there is evidence this vulnerability is being actively used in real-world attacks.

While CISA's directives formally apply only to US federal agencies, the agency encourages all organisations, including Australian businesses, to treat KEV listings as a priority patching signal. Many small and medium businesses use GitLab for source code management and DevOps workflows, making this a relevant risk for any team running the platform, whether self-hosted or in a private cloud environment.

Organisations using GitLab should check which version they are running and apply available security updates as soon as possible. Because this flaw is already being exploited, delays in patching increase the risk of compromise.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.