Threat Intelligence

Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure

The Hacker News · 12 Sept 2026
Key Takeaway If your business runs a self-managed GitLab instance exposed to the internet, patch immediately or restrict public access until you do.

GitLab has released patches for several security flaws, including a maximum-severity vulnerability (CVE-2026-85706, CVSS 10.0) in its repository commits API. The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server, provided at least one public project exists on that instance. Security researchers at watchTowr say active probing began within hours of the disclosure, with attackers using the flaw to access log files and configuration files that can contain credentials, secrets, and other sensitive information.

This marks the second critical GitLab vulnerability disclosed in recent weeks, following an actively exploited GraphQL code injection flaw. Researchers note that GitLab instances are an attractive target because successful exploitation can expose source code, CI/CD secrets, and credentials, potentially allowing attackers to tamper with software build pipelines and compromise anything downstream.

GitLab has also patched a separate critical flaw (CVE-2026-87719, CVSS 9.9) affecting the Enterprise Edition, which involves insecure deserialization that could let an authenticated user with Duo Chat access obtain sensitive configuration data and credentials. Patches are available in versions 19.3.2, 19.2.6, and 19.1.8.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.