Urgent Patch Needed: GitLab Vulnerability CVE-2026-85706 Faces Imminent Exploitation
September 14, 2026
WatchTowr Intel reported in-the-wild probes for CVE-2026-85706, signaling imminent exploitation, and provided indicators of compromise such as suspicious HTTP POST requests to /api/v4/projects/{id}/repository/commits/ with file.path parameters.
CISA issued a three-day window for government users to apply the patch.
GitLab released patches in CE/EE versions 19.3.2, 19.2.6, and 19.1 to fix the vulnerability and other issues, including an Insecure Deserialization issue in the GraphQL subscription serializer.
The advisory notes that GitLab did not explicitly state active exploitation, while independent researchers warned of ongoing attempts.
CISA added CVE-2026-85706 to its KEV catalog due to active exploitation.
The flaw is a critical path traversal in the repository commits API that allows unauthenticated attackers to read sensitive files.
Summary based on 1 source
