CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately
- CISA added GitLab CVE‑2026‑85706, a critical path traversal flaw, to its KEV catalog
- Exploitation already observed; attackers can read sensitive files via commits API without authentication
- GitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to update
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog, warning users that it is being actively exploited in the wild.
GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities. Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer.
The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE