GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026 — the agency's public statement that a maximum-severity flaw in GitLab is being used in real attacks. GitLab's own patch advisory describes the bug as a path traversal issue in the repository commits API: improper path confinement and missing authentication enforcement could let an unauthenticated user read arbitrary files from the GitLab server. GitLab scores it 10.0 out of 10.0 on CVSS, the highest the scale allows. CISA's catalog entry classifies it as CWE-35.
The sequence is what makes the case urgent. GitLab shipped the fixes on September 10, 2026, in versions 19.1.8, 19.2.6 and 19.3.2 for both Community Edition and Enterprise Edition. CISA listed the vulnerability as actively exploited one day later and set September 14, 2026 as the remediation date for US federal civilian agencies under Binding Operational Directive 26-04. The catalog entry also flags the CVE for forensic triage under that directive, which obliges agencies to check whether attackers compromised the system before the patch went on.
The exposure sits with organisations that run GitLab on their own infrastructure. GitLab lists the affected builds as 18.7 through 19.1.7, 19.2.0 through 19.2.5, and 19.3.0 through 19.3.1, and says GitLab.com already runs the patched code while GitLab Dedicated customers need take no action. A self-managed server is a dense target: it typically holds source code, CI/CD variables, deployment keys and integration tokens, which is precisely the material an unauthenticated file read can reach. The same release closed a second critical issue, CVE-2026-87719, rated 9.9 — according to GitLab, an authenticated user with Duo Chat access could obtain Advanced Search instance configurations and credentials through a crafted GraphQL subscription argument.
What remains unknown is who is exploiting the flaw, on what scale and against which organisations. No official statement names an attacker or a victim, and CISA's entry lists known ransomware campaign use as "Unknown". GitLab credits the researcher s3ntago with reporting the issue through its HackerOne bug bounty programme. Company policy is to publish the underlying issue-tracker entries 90 days after the release that patched them, which would put technical detail on CVE-2026-85706 around December 2026; until then, the upgrade is the only published remedy. The September 14 date binds US federal civilian agencies only — for everyone else, the KEV listing is CISA's signal that exploitation is already under way rather than theoretical.
Sources
- GitLab — Critical Patch Release: 19.3.2, 19.2.6, 19.1.8Primary source
- CISA — Adds One Known Exploited Vulnerability to CatalogPrimary source
- CISA — Known Exploited Vulnerabilities CatalogPrimary source
Related
Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22
Trending now
- Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
- Zverev Beats Shelton in 4 Sets for First US Open Title
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
- Treasury Yield Tops 5.014%, Highest Since 2023, Then Retreats
- US Diesel Sets Record $6.23 a Gallon, AAA Figures Show
Comments
No comments yet. Be the first.