Back to Feed
VulnerabilitiesSep 11, 2026

GitLab Vulnerability Exploited One Day After Disclosure

GitLab path traversal vulnerability (CVE-2026-85706) is being exploited one day after disclosure.

Summary

Threat actors have begun exploiting a critical path traversal vulnerability in GitLab, tracked as CVE-2026-85706, just one day after its public disclosure and patching. The flaw allows unauthenticated attackers to read arbitrary files from affected GitLab servers. This exploitation follows closely behind the patching of another critical insecure deserialization vulnerability (CVE-2026-87719) and numerous other high-severity defects.

Full text

Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns. Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server. All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected. On Friday, one day after GitLab announced patches for the security weakness, WatchTowr observed the first in-the-wild exploitation attempts targeting it. “WatchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,” the company said. According to WatchTowr, mass exploitation of the vulnerability is likely to follow shortly.Advertisement. Scroll to continue reading. “Defenders should hunt through log files for HTTP POST requests to ‘/api/v4/projects/{id}/repository/commits/’ URIs containing ‘file.path’ parameters to identify potential exploitation attempts,” the company noted. Self-hosted GitLab instances should be upgraded as soon as possible, as the fresh patches resolve 17 other vulnerabilities, including another critical-severity bug. The critical flaw, tracked as CVE-2026-87719 (CVSS score of 9.9/10), is an insecure deserialization issue in the GraphQL subscription serializer that could allow attackers to access “Advanced Search instance configurations and sensitive credentials”. GitLab CE/EE versions 19.1.8, 19.2.6, and 19.3.2 also resolve six high-severity security defects that could allow attackers to achieve remote code execution, access protected CI/CD variables, mount XSS attacks, and cause denial-of-service conditions. Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review Related: Check Point Patches Critical VPN Vulnerabilities Related: PaperCut Flaws Exploited in AI-Powered Attacks Related: Critical NetScaler Vulnerability Exploited in Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire PaperCut Flaws Exploited in AI-Powered AttacksCritical NetScaler Vulnerability Exploited in Attacks4.1 Million Impacted by AdaptHealth Data BreachNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and SecurityAndroid’s September 2026 Updates Patch 180 VulnerabilitiesChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories Latest News Phishing Research Challenges Conventional Security Awareness TestingIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings ReviewTrezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonCheck Point Patches Critical VPN VulnerabilitiesKiteworks Acquires Bonfy.AI to Fill the AI Gap in Data GovernanceSurfshark Systems Targeted by HackersAnthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-85706
  • cve — CVE-2026-87719

Entities

GitLab (product)GitLab (vendor)