LmCast :: Stay tuned in

CISA: Hackers now exploit max severity GitLab flaw in attacks

Recorded: Sept. 14, 2026, 7:09 a.m.

Original Summarized

CISA: Hackers now exploit max severity GitLab flaw in attacks

News

Featured
Latest

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

September Windows Server updates break Remote Desktop Services

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Stick with the language lessons that come from linguists in this app deal

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Get 3 years of Surfshark VPN for $67.19 in this deal

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCISA: Hackers now exploit max severity GitLab flaw in attacks

CISA: Hackers now exploit max severity GitLab flaw in attacks

By Sergiu Gatlan

September 14, 2026
03:06 AM
0

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
GitLab's DevSecOps platform is used by over 50% of Fortune 100 companies and has over 30 million registered users worldwide.
The security flaw (tracked as CVE-2026-85706) stems from missing authentication enforcement and improper path confinement in the repository commits API, and unauthenticated attackers can exploit it to read credentials, secrets, and other sensitive information from vulnerable servers.
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
While the company has yet to tag this vulnerability as actively exploited, cybersecurity firm watchTowr reported one day later that attackers were probing the Internet for GitLab servers unpatched against CVE-2026-85706.
"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," it warned.
"Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."
That same day, CISA added the vulnerability to its catalog of actively exploited flaws, giving government agencies three days to secure their systems under Binding Operational Directive (BOD) 26-04.
Although BOD 26-04 targets only federal agencies, CISA encouraged all network defenders, including those in the private sector, to patch their devices as soon as possible against ongoing attacks.
"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," it said. "While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities."
In January, GitLab also patched a high-severity two-factor authentication bypass flaw that enables attackers who know the target's account ID to circumvent two-factor authentication.
Since November 2021, CISA has tagged four GitLab vulnerabilities as actively exploited, including two (CVE-2021-22175 and CVE-2021-39935) in February this year.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
GitLab urges users to patch max severity path traversal flawCISA: WatchGuard RCE flaw now exploited in ransomware attacksCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayHackers now exploit critical Gitea flaw in code injection attacksCISA orders urgent patching of actively exploited Zimbra flaw

Actively Exploited
CISA
GitLab
Path Traversal

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Hackers abused Claude to extract secrets from 1.8M Android apps

GitLab urges users to patch max severity path traversal flaw

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning indicating that malicious actors are currently exploiting a maximum-severity vulnerability within GitLab, a platform widely utilized by over fifty percent of Fortune 100 companies and boasting more than thirty million registered users globally. This critical security flaw, tracked as CVE-2026-85706, arises from deficiencies in the repository commits API related to missing authentication enforcement and improper path confinement. Consequently, unauthenticated attackers can leverage this vulnerability to access and read sensitive data, including credentials, secrets, and other confidential information stored on vulnerable GitLab servers.

GitLab addressed this security issue by releasing patches for versions 19.3.2, 19.2.6, and 19.1 on Thursday, urging all users to implement these updates immediately. Despite the platform's remediation, cybersecurity firm watchTowr reported that attackers were actively probing the internet for GitLab servers that remained unpatched against CVE-2026-85706 just one day later, suggesting an imminent risk of indiscriminate exploitation. watchTowr warned that similar GitLab vulnerabilities suggest that the timescale until mass exploitation is likely short, advising defenders to actively search log files for specific HTTP POST requests to URIs containing 'file.path' parameters to identify potential exploitation attempts.

In response to this threat landscape, CISA formally added the specific vulnerability to its catalog of actively exploited flaws, providing government agencies with three days to secure their systems under the Binding Operational Directive (BOD) 26-04. Although BOD 26-04 is intended for federal agencies, CISA strongly encourages all organizations, including the private sector, to adopt a risk-based vulnerability management strategy and prioritize the remediation of vulnerabilities listed in the KEV Catalog. This emphasis stems from the recognition that these types of flaws serve as frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Furthermore, CISA has a history of tagging multiple GitLab vulnerabilities as actively exploited, noting that they tagged four such vulnerabilities since January, including two in February of the current year. Prior to this incident, GitLab had also patched a high-severity flaw in January that allowed attackers to bypass two-factor authentication if they knew the target account ID.