INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitLab CVE-2026-85706 Exploit Within 24 Hours
| 2026-09-14 10:00 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalog, a critical list of vulnerabilities that can compromise the security of software systems. This particular vulnerability is described as an "improper limitation of a pathname to a restricted directory" or "path traversal" flaw, which allows attackers to access arbitrary files on affected systems. The issue was first reported in September 2026 and has been under active exploitation for approximately 24 hours. CISA recommends that customers identify potential exploitation attempts by monitoring log files for HTTP POST requests containing "[IOC HIDDEN • LOGIN REQUIRED]" parameters and patch the vulnerability as soon as possible, with a deadline of September 15.
Technical Mitigations AI-generated
* Implement a secure authentication and authorization mechanism to ensure only authorized users can access sensitive data, such as SSH keys, database credentials, and deploy tokens.
* Regularly monitor log files for suspicious HTTP POST requests to "/api/v4/projects/{id}/repository/commits/" URIs containing "<a href="/auth/login?next=/detail/vvcmlKABGvYhsJJTQUrp" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>" parameters, and take immediate action if potential exploitation attempts are detected.
* Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and block in-the-wild probes of the GitLab path traversal vulnerability CVE-2026-85706.
* Implement rate limiting on HTTP requests to "/api/v4/projects/{id}/repository/commits/" URIs containing "<a href="/auth/login?next=/detail/vvcmlKABGvYhsJJTQUrp" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>" parameters, to prevent attackers from exploiting the vulnerability by making multiple requests within a short time frame.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fi•••••.path
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-85706CVE-2026-85706
CVE-2021-39935CVE-2021-39935
CVE-2021-22175CVE-2021-22175
CVE-2026-87719CVE-2026-87719
CVE-2023-2825CVE-2023-2825
CVE-2026-19478CVE-2026-19478
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
at least 2007
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours.
Click on any entity below to view its context and source!
attribution
CISA
One year later, CISA and the FBI urged software companies
to weed out path traversal security vulnerabilities
from their products before shipping, saying that such flaws "have been called 'unforgivable' since at least 2007.
attribution
FBI
One year later, CISA and the FBI urged software companies
to weed out path traversal security vulnerabilities
from their products before shipping, saying that such flaws "have been called 'unforgivable' since at least 2007.
November 2021
Threat actors exploited CVE-2021-22175 and CVE-2021-39935 vulnerabilities in GitLab within 24 hours.
Click on any entity below to view its context and source!
vulnerability
CVE-2021-22175
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged four GitLab vulnerabilities as exploited in attacks, including two (
CVE-2021-22175
and
CVE-2021-39935
) in February this year.
vulnerability
CVE-2021-39935
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged four GitLab vulnerabilities as exploited in attacks, including two (
CVE-2021-22175
and
CVE-2021-39935
) in February this year.
May 2023
Threat actors exploited CVE-2023-2825 in GitLab within 24 hours.
Click on any entity below to view its context and source!
vulnerability
CVE-2023-2825
"
In May 2023, GitLab
addressed another maximum severity path traversal flaw
(CVE-2023-2825) that exposes sensitive data, including proprietary software code, user credentials, tokens, and files on unpatched servers.
September 10
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours.
September 10, 2026
Threat actors exploited the GitLab CVE-2026-85706 vulnerability within 24 hours.
Click on any entity below to view its context and source!
organisation
CVE-2026-85706
GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API.
organisation
API
GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API.
vulnerability
CVSS 10.0
GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API.
2026/09/10
Threat actors exploited a previously unknown vulnerability in GitLab's GraphQL subscription serializer.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-87719
"
Yesterday, GitLab patched a second critical vulnerability tracked as
CVE-2026-87719
that stems from an insecure deserialization weakness in the GraphQL subscription serializer.
September 11
Threat actors used a known vulnerability in GitLab to exploit CVE-2026-85706 within 24 hours.
Click on any entity below to view its context and source!
organisation
Cybersecurity
Cybersecurity vendor WatchTowr said on September 11 that it had already detected “in-the-wild probes” for the critical bug.
organisation
WatchTowr
Cybersecurity vendor WatchTowr said on September 11 that it had already detected “in-the-wild probes” for the critical bug.
vulnerability
CVE-2026-85706
Update September 11, 09:39 EDT: Added watchTowr's report of CVE-2026-85706 probing.
organisation
Update
Update September 11, 09:39 EDT: Added watchTowr's report of CVE-2026-85706 probing.
Sep 11, 2026
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours.
September 11, 2026
Threat actors exploited CVE-2026-85706 in all versions of GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.7 before 19.1.8 to 19.3 before 19.3.2 within 24 hours.
Click on any entity below to view its context and source!
infrastructure
18.7
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
infrastructure
19.1.8
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
infrastructure
19.2
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
infrastructure
19.2.6
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
infrastructure
19.3
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
infrastructure
19.3.2
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
organisation
GitLab Community Edition (CE
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
organisation
UTC
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal vulnerability, was exploited within 24 hours of its disclosure by threat actors targeting affected systems via one HTTP request with no authentication and full file read access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85706
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Pierluigi Paganini
September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
organisation
GitLab
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Pierluigi Paganini
September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
vulnerability
CVSS 10.0
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Pierluigi Paganini
September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
organisation
CVSS
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Pierluigi Paganini
September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
general_metric
24 Hours
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Pierluigi Paganini
September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
2026/09/14
GitLab CVE-2026-85706 Exploit Within 24 Hours.
Click on any entity below to view its context and source!
organisation
CVE-2026-85706
CVE-2026-85706 is described as an “improper limitation of a pathname to a restricted directory,” or “path traversal” flaw.
organisation
Intel
“
watchTowr
Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request.”
"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,"
it warned
.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CVE-2026-85706)
organisation
API
The vulnerability in question is
CVE-2026-85706
(CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under certain conditions.
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
The security flaw, discovered by a security researcher using the '
s3ntago
' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API.
organisation
Unauthenticated
Unauthenticated attackers can exploit
CVE-2026-85706
"under certain conditions" to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers.
infrastructure
18.7
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.1.8
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
infrastructure
19.2
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.2.6
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
infrastructure
19.3
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
infrastructure
19.3.2
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
organisation
GitLab CE/EE
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
organisation
CVSS
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
infrastructure
9.9
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
organisation
GitLab Community Edition (CE
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
infrastructure
19.1
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
organisation
HackerOne
The security flaw, discovered by a security researcher using the '
s3ntago
' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API.
organisation
POST
Defenders should also check logs for suspicious POST requests to GitLab’s repository commit API containing
file.path
parameters, which may indicate exploitation attempts.
organisation
Hackers Exploit Maximum Severity
Hackers Exploit Maximum Severity Flaw in GitLab.
organisation
GitLab
GitLab users are being urged to patch a maximum severity vulnerability in the platform after reports of “in-the-wild” exploitation.
Ravie Lakshmanan
Sep 11, 2026
Vulnerability / Web Security
GitLab has
released patches
to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.
GitLab urges users to patch max severity path traversal flaw.
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Sep 11, 2026
Vulnerability / Web Security
GitLab has
released patches
to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.
organisation
Shutterstock.com
Image credit:
Samuel Boivin / Shutterstock.com
financial
04 BOD
“Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable,” CISA recommended.
organisation
Duo Chat
CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
The vulnerability could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup," GitLab said.
organisation
Advanced Search
CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
The vulnerability could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup," GitLab said.
organisation
CVE-2026
CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
organisation
CVE-2023-2825
CVE-2023-2825, which also allowed arbitrary file reads, faced active attacks just days after disclosure.
organisation
SSH
A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data.
organisation
CI
A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data.
"
"The appeal to attackers of GitLab is obvious, as unauthorized access allows an attacker to gain access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines, gaining access or poisoning anything downstream of it, which as we've seen throughout this year has been a favorite of attackers.
organisation
GitLab.com
"GitLab.com is already running the patched version.
organisation
Airbus
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
organisation
T-Mobile
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
organisation
Lockheed
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
organisation
Goldman Sachs
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
organisation
UBS
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
victims
30 registered users
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
September 15
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours, targeting civilian federal agencies with a deadline of September 15.
Click on any entity below to view its context and source!
attribution
KEV
Only civilian federal agencies are mandated to fix KEV vulnerabilities, in this case with a deadline of September 15.
Tactical Metrics
Metrics
infrastructure
18.7
Software Version
Click for context!
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
Metrics
infrastructure
19.1.8
Software Version
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
Metrics
infrastructure
19.2
Software Version
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
Metrics
infrastructure
19.2.6
Software Version
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
Metrics
infrastructure
19.3
Software Version
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
Metrics
infrastructure
19.3.2
Software Version
“GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” a security advisory noted.
All Community Edition and Enterprise Edition versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
"
The issue impacts the following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) -
All versions from 18.7 before 19.1.8,
All versions from 19.2 before 19.2.6, and
All versions from 19.3 before 19.3.2
According to preemptive exposure management firm watchTowr, the vulnerability is
already witnessing
active in-the-wild probes since 06:00 UTC on September 11, 2026.
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
Metrics
financial
4
Bod
“Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable,” CISA recommended.
Metrics
infrastructure
9.9
Software Version
"
Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.
Metrics
infrastructure
19.1
Software Version
Admins warned to patch as soon as possible
GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
Metrics
victims
30,000,000
Registered Users
The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including Nvidia, Airbus, T-Mobile, Lockheed Martin, Goldman Sachs, and UBS.
Intelligence Sources
Infosecurity-Magazine
2026-09-14
Hackers Exploit Maximum Severity Flaw in GitLab
Infosecurity-Magazine
Security Affairs
2026-09-13
The Hacker News
2026-09-11
BleepingComputer
2026-09-11
GitLab urges users to patch max severity path traversal flaw
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-15T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
33x
organisation
Identified Entity
CVE-2026-85706
entity
12x
timeline
Temporal Reference
September 10
date
8x
attribution
Attributing Entity
the US Cybersecurity and Infrastructure Security Agency
authority
8x
infrastructure
Software Version
18.7
version
6x
vulnerability
Exploited CVE
CVE-2026-85706
cve
2x
general metric
19.2.6
19
19.2.6
Contextual Telemetry
Context Block
13 METRICS
source region
Origin Country
United States
country
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Cve-2026
85,706
cve-2026
general metric
Versions
19
versions
financial
Bod
4
bod
vulnerability
CVSS Score
10
score
general metric
Hours
24
hours
general metric
Score
10
score
general metric
Draws Wild Probes
10
draws wild probes
general metric
Sep
11
sep
victims
Registered Users
30,000,000
registered users
general metric
%
50
%
general metric
Fortune
100
fortune
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.