CISA: Hackers now exploit max severity GitLab flaw in attacks
Reported exploitedGitLab CEGitLab EEOur summary
CISA has designated CVE-2026-85706, a critical path traversal vulnerability in GitLab Community Edition and Enterprise Edition, as actively exploited in the wild. The flaw allows unauthenticated attackers to access sensitive data such as credentials and secrets via the repository commits API by bypassing proper path confinement. Fixed versions have been released for 19.3.2, 19.2.6, and 19.1, prompting immediate remediation recommendations for both government and private sector users.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.