A maximum-severity flaw in GitLab's Community and Enterprise editions, patched September 10, is being actively exploited to pull arbitrary files from self-hosted GitLab servers without authentication. WatchTowr researchers say attackers have moved from probing to full exploitation, extracting configuration files, secrets, and SSH settings from compromised systems. CISA has added the bug to its Known Exploited Vulnerabilities list, ordering federal agencies to patch or take affected instances offline.
darkreading.com
· 2026-09-14
CISA has added a maximum-severity GitLab vulnerability, CVE-2026-85706, to its known exploited vulnerabilities catalog after security firm watchTowr detected attackers scanning the internet for unpatched servers. The flaw allows unauthenticated attackers to read credentials and sensitive files from GitLab instances via a single crafted HTTP request to the repository commits API. GitLab patched the issue in versions 19.3.2, 19.2.6, and 19.1, but federal agencies now have just three days to remediate under a binding directive.
bleepingcomputer.com
· 2026-09-14
GitLab issued emergency patches for CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary files on vulnerable servers. The company also fixed a second critical bug, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer that could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both flaws are addressed in versions 19.3.2, 19.2.6, and 19.1.
bleepingcomputer.com
· 2026-09-11