CISA: Hackers Now Exploit Max Severity GitLab Flaw in Attacks
8 Articles
8 Articles
GitLab CVE-2026-85706 moves from disclosure to exploitation in 24 hours
GitLab disclosed CVE-2026-85706 on 10 September: a CVSS 10.0 path traversal flaw in the repository commits API allowing arbitrary file reads via a single unauthenticated HTTP request. Affected branches include 18.7 before 19.1.8, 19.2 before 19.2.6...
GitLab's Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing
GitLab administrators got an unwelcome reminder this week that a single API endpoint can undo years of access control work. On September 10, GitLab shipped a critical patch release — versions 19.3.2, 19.2.6 and 19.1.8 — to fix 18 security vulnerabilities, two of them rated critical. One of those two is about as bad as a vulnerability gets: an unauthenticated attacker can read arbitrary files off a self-managed GitLab server without so much as a …
CISA: Hackers now exploit max severity GitLab flaw in attacks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. GitLab's DevSecOps platform is used by over 50% of Fortune 100 companies and has over 30 million registered users worldwide. The security flaw (tracked as CVE-2026-85706) stems from missing authentication enforcement and improper path confinement […] Thank you for subscribing to our RSS feed!
GitLab has released an emergency patch to fix a major security flaw (CVE-2026-85706, CVSS 10.0 score) affecting its commit API. Hackers are already exploiting this breach to read sensitive server files. Companies using auto-hosted instances must apply the update immediately under penalty of imminent hacking.
Coverage Details
Bias Distribution
- 50% of the sources are Center, 50% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium










