CISA has added a critical GitLab vulnerability, CVE-2026-85706, to its Known Exploited Vulnerabilities list after reports of in-the-wild probes and active exploitation. GitLab released a patch on Sept. 10 and assigned the flaw a CVSS score of 10.0. Security firms and HKCERT warn attackers can access files and extract credentials; organizations should patch immediately, rotate secrets, and investigate possible compromises.
CISA Warns: Critical GitLab Flaw (CVE-2026-85706) Is Being Exploited — Patch Now

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and other security teams are warning that threat actors have begun exploiting a critical vulnerability in the GitLab development platform.
What Happened
CISA added the vulnerability tracked as CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalog, directing federal agencies to mitigate the risk immediately. GitLab released a security update for the flaw on Sept. 10.
Why It’s Critical
GitLab assigned the vulnerability a maximum CVSS score of 10.0. The flaw stems from missing authentication checks and insufficient restrictions on where users can place files, which can allow unauthenticated attackers to read files on affected GitLab servers.
Evidence Of Active Exploitation
Security firm watchTowr reported that its analysts were already seeing "in-the-wild probes" targeting servers running vulnerable GitLab versions. The firm warned attackers could read local files and configuration data to obtain credentials, secrets, and other sensitive information.
"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away," watchTowr said.
Hong Kong's computer emergency response team (HKCERT) also issued an advisory saying the vulnerability is "being exploited in the wild."
Related Fixes and History
In the same update, GitLab patched a second issue, CVE-2026-87719, which could expose sensitive information on instances running GitLab's Enterprise Edition. These incidents follow multiple serious disclosures affecting GitLab in 2025–2026, including CVE-2025-0376, CVE-2026-1092, CVE-2025-12664, CVE-2026-5173 and CVE-2026-19478 (the latter reported exploited within days of disclosure).
Recommended Actions
- Patch Immediately: Apply the GitLab update released Sept. 10 or any later security patch that addresses CVE-2026-85706 and CVE-2026-87719.
- Prioritize Exposed Instances: Remediate internet-facing GitLab servers first and apply network controls to limit access until patches are installed.
- Rotate Credentials and Secrets: Assume potential exposure of credentials and rotate keys, tokens, and passwords that may have been stored on affected systems.
- Hunt and Monitor: Review logs for unusual file access and scanning activity. Look for indicators of compromise and anomalous reads of configuration files.
- Follow Vendor Guidance: Use GitLab’s official advisory and CISA guidance for detailed mitigation steps and version information.
Bottom Line
This is a high-risk, actively exploited vulnerability. Organizations running GitLab should treat it as an immediate priority: apply vendor patches, investigate for signs of compromise, and enforce tighter access controls until systems are confirmed secure.
Help us improve.



























