www.securityweek.com 11 Sept 2026, 16:11 UTC

Attackers Exploit Critical GitLab Flaw Within a Day of Patches

Attackers Exploit Critical GitLab Flaw Within a Day of Patches
CyberSIXT Evidence Panel Source marked as original reporting

SECURITYWEEK reports that a critical path traversal vulnerability in GitLab, tracked as CVE-2026-85706 with a CVSS score of 10/10, was exploited in the wild barely a day after GitLab disclosed patches. The flaw allows unauthenticated attackers to read arbitrary files from the GitLab server via a single HTTP request. The issue affects all Community Edition (CE) and Enterprise Edition (EE) releases from 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2.

WatchTowr Intel reported observing in-the-wild exploitation attempts shortly after the patch release, indicating attackers were actively scanning for and attempting to exploit the vulnerability.

The GitLab patches also address CVE-2026-87719, an insecure deserialization flaw in the GraphQL subscription serializer with a CVSS of 9.9/10, which could expose advanced search instance configurations and sensitive credentials. The fixed CE/EE versions for this flaw are 19.1.8, 19.2.6 and 19.3.2, and the updates additionally resolve six high-severity defects that could enable remote code execution, access to protected CI/CD variables, cross-site scripting, and denial-of-service conditions.

Defenders are advised to upgrade promptly and to watch logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ containing file[.]path parameters, which WatchTowr described as indicative of exploitation attempts.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline