INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Maximum Severity GitLab Flaw Exploited in Attacks

| 2026-09-14 20:19 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent exploitation of a maximum-severity GitLab vulnerability has significant implications for organizations with self-managed instances. The CVE-2026-85706 flaw, disclosed last week and patched on September 10, allows unauthenticated individuals to read arbitrary files from the server. This could compromise sensitive information like passwords and CI/CD secrets, potentially granting attackers further access into downstream systems. Organizations are urged to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for Community Edition and Enterprise Editions. The vulnerability exists in both CE and EE, which organizations use to set up self-hosted instances within their environments. Threat actors could exploit this flaw by dumping config files with secrets and system SSH configurations, compromising sensitive information.
Technical Mitigations AI-generated
* Implement authentication and authorization: Ensure that all users have proper access controls, including authentication checks on repository commits API, to prevent unauthorized access to public projects. * Regularly update GitLab instances: Update self-hosted GitLab instances to the latest versions (19.3.2, 19.2.6, or 19.1.8) for Community Edition and Enterprise Edition to ensure patching of CVE-2026-85706. * Monitor access logs: Regularly review access logs on the repository commits API for suspicious or unauthenticated requests that suggest probing or exploitation activity. * Use secure configuration options: Consider using secure configuration options, such as "public" projects, in GitLab to limit exposure and restrict access to sensitive areas of the platform.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

fi•••••.path
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cyclops BlinkCyclops Blink CVE-2026-85706CVE-2026-85706 CVE-2026-87719CVE-2026-87719 CVE-2021-22175CVE-2021-22175 CVE-2021-39935CVE-2021-39935 CVE-2026-19478CVE-2026-19478
Target & Sectors
Global Scope governmentgovernment technologytechnology
Incident Timeline
‎November 2021
Threat actors exploited the CVE-2021-22175 and CVE-2021-39935 vulnerabilities in GitLab.
vulnerability CVE-2021-22175
vulnerability CVE-2021-39935
‎2026/08/15
Attackers exploited CVE-2026-19478, a GraphQL code injection flaw.
vulnerability CVE-2026-19478
‎2026/09/07
Threat actors are exploiting a maximum-severity vulnerability in GitLab that was disclosed last week.
‎Sept. 10
Threat actors exploited a path traversal flaw in GitLab's CVE-2026-85706 to gain unauthorized access.
vulnerability CVE-2026-85706
organisation GitLab
‎Sept. 11, 2026
Threat actors exploited a critical flaw in the GitLab software.
‎2026/09/14
Threat actors exploited a critical flaw in GitLab, targeting affected systems and requiring immediate patching or disabling.
vulnerability CVE-2026-85706
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
general_metric 85706 CVE-2026
‎2026/09/14
GitLab exploited a critical flaw in its repository commits API, allowing attackers to read arbitrary files and gain access to sensitive information.
organisation CVE-2026
organisation CI
organisation WatchTowr
organisation API
organisation Intel
organisation GitLab
infrastructure 19.3.2
infrastructure 19.2.6
infrastructure 19.1.8
organisation GitLab Community Edition (CE
infrastructure 19.1
infrastructure 18.7
infrastructure 19.2
infrastructure 19.3
organisation CVSS
organisation SSH
organisation POST
financial 04 BOD
organisation NFL
organisation CHANEL
victims 30 registered users
victims 26 targets
organisation GitLab’s Enterprise Edition
infrastructure 18.3
infrastructure 9.9
organisation Community Edition and Enterprise Edition
organisation Duo Chat
organisation Advanced Search
Tactical Metrics
Metrics
infrastructure
‎19.3.2
Software Version
Metrics
infrastructure
‎19.2.6
Software Version
Metrics
infrastructure
‎19.1.8
Software Version
Metrics
infrastructure
‎19.1
Software Version
Metrics
financial
4
Bod
Metrics
victims
30,000,000
Registered Users
Metrics
victims
26
Targets
Metrics
infrastructure
‎18.7
Software Version
Metrics
infrastructure
‎19.2
Software Version
Metrics
infrastructure
‎19.3
Software Version
Metrics
infrastructure
‎18.3
Software Version
Metrics
infrastructure
‎9.9
Software Version
Intelligence Sources