Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Critical GitLab Flaw Actively Exploited, CISA Warns

Published 14 September 2026

A critical vulnerability in GitLab's widely used DevSecOps platform is being actively exploited in the wild, prompting urgent warnings from U.S. cybersecurity authorities and security researchers. The flaw, tracked as CVE-2026-85706, carries a maximum severity score of 10.0 and allows unauthenticated attackers to read arbitrary files from vulnerable self-managed GitLab servers. GitLab released patches for the vulnerability on September 10, 2026, in versions 19.3.2, 19.2.6, and 19.1.8. The company urged immediate upgrades for self-hosted instances, noting that its GitLab.com service and dedicated cloud customers are not affected. The vulnerability resides in the repository commits API, where missing authentication checks and improper path confinement enable attackers to craft requests that access files anywhere on the server's filesystem. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, confirming active exploitation. Federal civilian agencies were given until September 15 to remediate the flaw under Binding Operational Directive 26-04.

0:00 / 0:00