Sizing Self-Managed GitLab Exposure After CVE-2026-85706
A vulnerability CVE-2026-85706 was found in GitLab: unauthenticated arbitrary file read via repository commit API, CVSS 10.0. Patches released on September 10, 2026, in versions 19.3.2, 19.2.6, and 19.1.8; the next day CISA added the vulnerability to its exploited catalog. According to ZoomEye, over 1.26 million matches of the GitLab fingerprint are visible online.
- CVE-2026-85706: unauthenticated file read, CVSS 10.0
- Fixed on September 10, 2026, in 19.3.2, 19.2.6, and 19.1.8
- CISA added vulnerability to exploited catalog on September 11
- ZoomEye: 1,262,273 matches of GitLab fingerprint in IPv4
Read next
Security