CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately

CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately

(Image credit: Shutterstock) CISA added GitLab CVE‑2026‑85706, a critical path traversal flaw, to its KEV catalogExploitation already observed; attackers can read sensitive files via commits API without authenticationGitLab patched in CE/EE 19.3.2, 19.2.6, and 19.1; agencies given three days to updateThe US Cybersecurity and Infrastructure Security Agency (CISA) has added a new GitLab vulnerability to its KEV catalog, warning users that it is being actively exploited in the wild.GitLab has now updated its Community Edition (CE) and Enterprise Edition (EE) versions to 19.3.2, 19.2.6, and 19.1, fixing a range of vulnerabilities. Among them were two critical-severity ones: a path traversal issue in repository commits API, and an Insecure Deserialization issue in GraphQL subscription serializer.The former is tracked as CVE-2026-85706, with a severity score of 10/10. It stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated threat actors to read various sensitive information such as login credentials or secrets.Added to KEVIn the advisory, GitLab did not mention anything about the flaws being abused in the wild - however, a separate report from cybersecurity experts watchTowr, released a day later, claimed so:"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request," the researchers said."Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away. [..] Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts."At the same time, CISA added this bug to its Known Exploited Vulnerabilities (KEV) catalog, confirming the claims and giving government users a tiny three-day window to apply the patch.Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!GitLab is an intelligent orchestration platform for DevSecOps professionals, helping organizations automate and streamline the software development cycle. It has more than 50 million registered users, among which are roughly 50% of Fortune 100 companies, as per an SEC filing.Via BleepingComputer Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Original Source

Read the full article at Techradar →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.