RAPID 7 reported on 14 September 2026 that a critical GitLab vulnerability, CVE-2026-85706, was being exploited in the wild. GitLab disclosed and patched the path-traversal flaw in its repository commits API on 10 September. Rated CVSS 10.0, the vulnerability could, under certain conditions, allow an unauthenticated attacker to read arbitrary files from an affected server because of inadequate path confinement and missing authentication enforcement.
The issue affects self-managed GitLab Community Edition and Enterprise Edition installations across Omnibus, source-code and Helm chart deployments. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 11 September, citing evidence of active exploitation, and set a 14 September remediation deadline for affected US federal civilian agencies, alongside forensic triage requirements. Rapid7 said CVE-2026-85706 was the only vulnerability in the release known to be exploited at the time of publication.
GitLab’s fixed versions are 19.1.8, 19.2.6 and 19.3.2, covering versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 respectively. GitLab.com is already patched, while GitLab Dedicated customers do not need to act. The updates include database migrations: single-node installations will experience downtime, while multi-node deployments can use GitLab’s zero-downtime procedure; only version 19.3.2 includes post-deployment migrations.
Rapid7 recommends emergency patching and checking for signs of compromise even after updating. It also noted that the release fixes 17 other vulnerabilities, including CVE-2026-87719, but said that flaw was not known to be exploited.