Critical GitLab flaw CVSS 10.0 exploited in the wild
GitLab CE/EE contains a path-traversal vulnerability CVE-2026-85706 rated CVSS 10.0 that lets an unauthenticated attacker read arbitrary files from the server. Patched on September 11, it was probed in the wild within hours and added by CISA to its Known Exploited Vulnerabilities catalog.
- Affected versions: 18.7–19.1.7, 19.2–19.2.5, 19.3–19.3.1
- Exploitation requires only one public project on the instance
- Fix: upgrade to 19.3.2, 19.2.6 or 19.1.8
- CISA added CVE-2026-85706 to its KEV catalog
Read next
Security