CISA KEV Alert 11 Sept 2026, 20:33 UTC

CISA Flags Actively Exploited GitLab Flaw Exposing Arbitrary Files

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA has added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects GitLab Community Edition and Enterprise Edition and allows unauthenticated users to read arbitrary files through the repository commits API.

The flaw is a path traversal vulnerability caused by improper path confinement and missing authentication enforcement. An attacker can exploit the API without authentication to access arbitrary files. No CVSS score or severity rating is available. The supplied data does not confirm patch availability, although GitLab has issued release guidance.

CISA has confirmed active exploitation by listing the CVE in the KEV catalogue. Ransomware use is unknown. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 14 September 2026.

CISA requires organisations to apply mitigations in accordance with vendor instructions, BOD 26-04 guidance on prioritising security updates based on risk, and CISA’s Forensics Triage Requirements. Agencies should follow applicable BOD 26-04 guidance for cloud services or discontinue use if mitigations are unavailable. FCEB agencies are directly affected, but all organisations should review their GitLab deployments and internet exposure.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline