GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for Community Edition and Enterprise Edition, remediating 18 vulnerabilities. The most severe, CVE-2026-85706 (CVSS 10.0), is an unauthenticated path-traversal flaw in the repository commits API that enables arbitrary file reads from vulnerable GitLab servers. GitLab also addressed authorization issues, cross-site scripting, CI/CD-variable exposure, and denial-of-service vulnerabilities.
Enterprise Edition fixes include CVE-2026-87719 (CVSS 9.9), an authenticated insecure-deserialization issue associated with Duo Chat/GraphQL subscription handling that can expose Advanced Search configuration and credentials, and CVE-2026-88765 (CVSS 8.5), which can allow authenticated remote code execution through importing a crafted malicious Git project export. GitLab.com already runs the patched release and GitLab Dedicated customers need take no action; self-managed administrators should upgrade immediately and plan for database migrations, which require downtime on single-node deployments.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
CISA required U.S. federal civilian executive branch agencies to remediate actively exploited GitLab CVE-2026-85706 and designated affected instances for forensic triage under Binding Operational Directive 26-04. The directive notes that pre-patch access may have exposed source code, CI/CD data, credentials, tokens, and other secrets.
CISA added GitLab CVE-2026-85706 to its Known Exploited Vulnerabilities Catalog after exploitation was observed. The Canadian Centre for Cyber Security advised GitLab administrators to apply the vendor's required updates promptly.
WatchTowr observed in-the-wild probes targeting GitLab CVE-2026-85706 one day after the vulnerability's public disclosure. The researchers warned that mass exploitation of the unauthenticated path-traversal flaw was likely to follow.
GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for Community Edition and Enterprise Edition, remediating 18 vulnerabilities. The fixes include CVE-2026-85706, a CVSS 10.0 unauthenticated repository-commits API path traversal that could permit arbitrary file reads; GitLab advised affected self-managed customers to upgrade immediately.
A ProjectDiscovery Nuclei template named "cve-2026-85706-nuclei-probe" was proposed to test GitLab instances for unauthenticated file-read behavior associated with CVE-2026-85706. The probe uses URL-escaped route components such as `%66iles`, `%63ommits`, and `%72epository`, and checks for the "local file not present" response marker.
GitLab disclosed CVE-2026-87719, a critical unsafe-deserialization vulnerability in the GitLab EE GraphQL subscription serializer. Authenticated users with Duo Chat access could obtain sensitive credentials and Advanced Search instance configuration; GitLab released updates for self-managed deployments, while GitLab.com was already patched and GitLab Dedicated was unaffected.
WatchTowr recommended that defenders review HTTP POST requests to `/api/v4/projects/{id}/repository/commits/` containing `file.Path` parameters as possible indicators of CVE-2026-85706 exploitation. The researchers also noted exploitation requires at least one public GitLab project.
WatchTowr stated that CVE-2026-19478, an unauthenticated GitLab GraphQL flaw that could modify or delete public project and user data, experienced active exploitation shortly after disclosure. GitLab had previously issued fixes in CE/EE versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
26 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcedocs.gitlab.com
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.