CVE Tools

CISA: Hackers now exploit max severity GitLab flaw in attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedGitLab CEGitLab EE

Our summary

CISA has designated CVE-2026-85706, a critical path traversal vulnerability in GitLab Community Edition and Enterprise Edition, as actively exploited in the wild. The flaw allows unauthenticated attackers to access sensitive data such as credentials and secrets via the repository commits API by bypassing proper path confinement. Fixed versions have been released for 19.3.2, 19.2.6, and 19.1, prompting immediate remediation recommendations for both government and private sector users.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store