Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
A critical flaw in GitLab, rated the highest possible severity score of 10.0, is being actively exploited by attackers just days after fixes were released. The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation and added the vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog.
The bug is a path traversal issue in GitLab's repository commits API, affecting both Community and Enterprise editions. Under certain conditions, attackers don't need to log in at all to read arbitrary files from a vulnerable server, potentially exposing source code, configuration files, and credentials. GitLab released fixes on September 10 in versions 19.3.2, 19.2.6 and 19.1.8. Security firm watchTowr has already spotted attackers probing internet-facing GitLab servers over the weekend and warns that broader exploitation is likely to follow quickly, noting that a single web request may be enough to trigger the flaw.
GitLab.com is already patched, and GitLab Dedicated customers do not need to take any action. However, organisations running self-managed GitLab instances that are exposed to the internet are at risk and should act immediately.