Security News

Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline

The Register · 15 Sept 2026
Key Takeaway If your business runs a self-hosted GitLab instance, patch it to the latest version immediately or take it offline from public access until you can.

A critical flaw in GitLab, rated the highest possible severity score of 10.0, is being actively exploited by attackers just days after fixes were released. The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation and added the vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog.

The bug is a path traversal issue in GitLab's repository commits API, affecting both Community and Enterprise editions. Under certain conditions, attackers don't need to log in at all to read arbitrary files from a vulnerable server, potentially exposing source code, configuration files, and credentials. GitLab released fixes on September 10 in versions 19.3.2, 19.2.6 and 19.1.8. Security firm watchTowr has already spotted attackers probing internet-facing GitLab servers over the weekend and warns that broader exploitation is likely to follow quickly, noting that a single web request may be enough to trigger the flaw.

GitLab.com is already patched, and GitLab Dedicated customers do not need to take any action. However, organisations running self-managed GitLab instances that are exposed to the internet are at risk and should act immediately.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.