Critical GitLab Flaw Under Active Attack: Patch Now
GitLab users are being urged to patch a maximum severity vulnerability after reports of active exploitation in the wild. CVE-2026-85706 is a path traversal flaw affecting GitLab CE/EE versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Due to improper path confinement and missing authentication checks in the repository commits API, an unauthenticated attacker could read arbitrary files from a vulnerable GitLab server. GitLab fixed the issue on September 10.
While GitLab has not confirmed exploitation itself, security vendor watchtower detected in-the-wild probes targeting the flaw on September 11, warning that widespread exploitation is likely to follow soon based on patterns seen with previous GitLab vulnerabilities. The vendor advised organisations to check log files for suspicious HTTP POST requests to repository commit API paths containing file path parameters, which may indicate exploitation attempts.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 15 to patch. Although this deadline only applies to US government bodies, CISA and security experts consider patching such vulnerabilities best practice for all organisations, particularly as AI tools are increasingly helping attackers weaponise new flaws faster than before.