Actively Exploited GitLab Vulnerability Added to US Government Threat List
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw, CVE-2026-85706, to its Known Exploited Vulnerabilities Catalog. The vulnerability affects GitLab Community Edition and Enterprise Edition and is classified as a path traversal issue, a type of bug that allows attackers to access files or areas of a system they shouldn't be able to reach. CISA confirmed there is evidence this vulnerability is being actively used in real-world attacks.
While CISA's directives formally apply only to US federal agencies, the agency encourages all organisations, including Australian businesses, to treat KEV listings as a priority patching signal. Many small and medium businesses use GitLab for source code management and DevOps workflows, making this a relevant risk for any team running the platform, whether self-hosted or in a private cloud environment.
Organisations using GitLab should check which version they are running and apply available security updates as soon as possible. Because this flaw is already being exploited, delays in patching increase the risk of compromise.