GitLab CVE-2026-85706: CVSS 10 flaw exploited in the wild

Following GitLab's September 11 disclosure of CVE-2026-85706 (path traversal, CVSS 10.0), by September 12, 2026, active exploitation probes were already being observed in the wild. CISA added it to the Known Exploited Vulnerabilities catalog with a three-day deadline for agencies to patch self-managed GitLab servers.

13 reports · 12 independentother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitLab patches critical CVE-2026-85706: CVSS 10.0 path traversal flaw exposes arbitrary files to unauthenticated users via repository commits API. Self-managed https:// deafnews.it/en/article/gitlab-

mastodon:infosec-exchangeother18d ago kagi ↗

GitLab patches critical CVE-2026-85706: CVSS 10.0 path traversal flaw exposes arbitrary files to unauthenticated users via repository commits API. Self-managed https:// deafnews.it/en/article/gitlab- patches-cve-2026-85706-path-traversal-cvss-100-in-self-managed-instances

🚨 Critical GitLab Security Alert GitLab has patched CVE-2026-85706, a CVSS 10.0 path traversal vulnerability** affecting self-managed installations. The flaw can allow an unauthenticated attacker to

mastodon:infosec-exchangeother18d ago kagi ↗

🚨 Critical GitLab Security Alert GitLab has patched CVE-2026-85706, a CVSS 10.0 path traversal vulnerability** affecting self-managed installations. The flaw can allow an unauthenticated attacker to read arbitrary files outside the intended repository path, potentially exposing sensitive configuration, credentials, source code, and CI/CD secrets. GitLab also fixed CVE-2026-87719, a CVSS 9.9 insec

CISA adds critical GitLab flaw to exploited catalog

kite:cybersecurityother18d ago kagi ↗

GitLab has patched CVE-2026-85706, a maximum-severity path-traversal vulnerability in its repository commits API that could allow an unauthenticated attacker to read arbitrary files from an affected server under certain conditions. The flaw received a CVSS score of 10.0 and affects self-managed Community Edition and Enterprise Edition releases before 19.1.8, 19.2.6 and 19.3.2. [thehackernews.com#1

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Communi

mastodon:infosec-exchangeother18d ago kagi ↗

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. ⠀ The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request. Affected versions include: • Git

🤖 CVE-2026-85706 (CVSS 10.0): path traversal in GitLab's repository commits API lets unauthenticated users read arbitrary files from the server. Patches out — in-the-wild probes observed within hours

mastodon:infosec-exchangeother18d ago wire ×2 kagi ↗

🤖 CVE-2026-85706 (CVSS 10.0): path traversal in GitLab's repository commits API lets unauthenticated users read arbitrary files from the server. Patches out — in-the-wild probes observed within hours of disclosure. 🔗 https:// thehackernews.com/2026/09/gitl ab-cvss-10-file-read-flaw-draws-in.html # CVE # CyberSec

⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API t

mastodon:infosec-exchangeother17d ago kagi ↗

⚠️ CRITICAL: GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without… https:// threa

⚠️ PATCH NOW GitLab shipped a critical patch: CVE-2026-85706 lets an unauthenticated attacker read files, including secrets, off a self-managed GitLab server (CVSS 10). Scanning for exposed servers ha

mastodon:infosec-exchangeother17d ago kagi ↗

⚠️ PATCH NOW GitLab shipped a critical patch: CVE-2026-85706 lets an unauthenticated attacker read files, including secrets, off a self-managed GitLab server (CVSS 10). Scanning for exposed servers has already begun. Self-managed GitLab is exposed. Patch to 19.3.2, 19.2.6, or 19.1.8 now. https:// suriq.io/blog/gitlab-cve-2026- 85706-unauth-file-read # CVE # infosec # cybersecurity

GitLab path-traversal CVE-2026-85706 (CVSS 10.0) is being exploited in the wild one day after disclosure. It allows unauthenticated arbitrary file read with a single HTTP request, exposing secrets and

mastodon:infosec-exchangeother17d ago kagi ↗

GitLab path-traversal CVE-2026-85706 (CVSS 10.0) is being exploited in the wild one day after disclosure. It allows unauthenticated arbitrary file read with a single HTTP request, exposing secrets and enabling further compromise. Prioritize immediate patching and review logs. # GitLab # PathTraversal # ThreatIntel https:// cyberworldops.eu/en/critical-g itlab-file-read-flaw-exploited-within-a-day-

GitLab Patches Critical Path Traversal Flaw Under Active Exploitation GitLab released emergency patches for 18 vulnerabilities, including a CVSS 10.0 path traversal flaw (CVE-2026-85706) that allows u

mastodon:infosec-exchangeother17d ago kagi ↗

GitLab Patches Critical Path Traversal Flaw Under Active Exploitation GitLab released emergency patches for 18 vulnerabilities, including a CVSS 10.0 path traversal flaw (CVE-2026-85706) that allows unauthenticated attackers to read sensitive server files and is currently seeing active probes. **If you run a self-hosted GitLab instance, update it now to version 19.3.2, 19.2.6, or 19.1.8. One of th

🔵 THREAT INTELLIGENCE GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Vulnerability | CRITICAL CVEs: CVE-2026-85706 GitLab has released patches to address multiple flaws, incl

mastodon:infosec-exchangeother17d ago kagi ↗

🔵 THREAT INTELLIGENCE GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Vulnerability | CRITICAL CVEs: CVE-2026-85706 GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes... Full analysis: https://www. yazoul.net/news/article/gitlab -cvss-10-file-read-flaw-draws-in-the-wild-probes-aft

That is a faster turnaround than most people's pizza delivery. Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel.

mastodon:infosec-exchangeother17d ago kagi ↗

That is a faster turnaround than most people's pizza delivery. Patch GitLab immediately to remediate CVE-2026-85706 — your self-managed server is the featured product in someone else's highlight reel. Reward: Complimentary sponsorship credit from Deferred Maintenance Inc. Your inaction keeps them in business. https://www. securityweek.com/gitlab-vulner ability-exploited-one-day-after-disclosure/ #

GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day dea

mastodon:infosec-exchangeother17d ago kagi ↗

GitLab CVE-2026-85706 is a maximum-severity path traversal in the repository commits API enabling unauthenticated arbitrary file read on self-managed servers. CISA added it to KEV with a three-day deadline, signaling active exploitation risk. Patch immediately and review for anomalous access to credentials and secrets. # GitLab # CisaKev # InfoSec https:// cyberworldops.eu/en/gitlab-pat h-traversa