CISA warns hackers are exploiting max severity GitLab flaw urges all businesses to patch immediately
Date:
Mon, 14 Sep 2026 16:50:00 +0000
Description:
A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter CISA added GitLab CVE202685706, a critical path traversal flaw, to its KEV catalog Exploitation already observed; attackers can read sensitive files via commits API without authentication GitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to update The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog,
warning users that it is being actively exploited in the wild.
GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities.
Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer. The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive information such as login credentials or secrets. Latest Videos From TechRadar Watch full video here: Added to KEV In the advisory, GitLab did not mention anything about the flaws being abused in the wild - however, a separate report from
cybersecurity experts watchTowr, released a day later, claimed so:
"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," the researchers said. You may like A potentially dangerous macOS security flaw went
unreported due to Apple being deluged by AI slop bug reports Cisco patches three critical vulnerabilities as part of 'comprehensive internal security review' NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft
"Based on recent GitLab vulnerabilities, we know the time until
indiscriminate exploitation is likely not far away. [..] Defenders should
also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."
At the same time, CISA added this bug to its Known Exploited Vulnerabilities (KEV) catalog, confirming the claims and giving government users a tiny three-day window to apply the patch. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
GitLab is an intelligent orchestration platform for DevSecOps professionals, helping organizations automate and streamline the software development cycle. It has more than 50 million registered users, among which are roughly 50% of Fortune 100 companies, as per an SEC filing .
Via BleepingComputer The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/cisa-warns-hackers-are-exploiting-max-s everity-gitlab-flaw-urges-all-businesses-to-patch-immediately
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)