GitLab patched CVE-2026-85706, a CVSS 10.0 vulnerability in the repository commits API that lets unauthenticated remote attackers bypass path restrictions and read arbitrary files from vulnerable self-managed GitLab CE and EE servers. CISA added the flaw to its Known Exploited Vulnerabilities catalog, while public proof-of-concept material, Nuclei templates, scanning, and attempted exploitation have increased the risk that exposed instances could leak secrets, CI/CD credentials, and deployment material.
Organizations should urgently upgrade to GitLab versions 19.1.8, 19.2.6, or 19.3.2, as applicable, and review API request logs for traversal attempts against commit endpoints. The releases also remediate critical flaws including CVE-2026-87719, an authenticated GitLab EE Duo Chat unsafe-deserialization issue, alongside other high-severity bugs that can enable remote code execution, configuration changes, CI/CD-variable access, denial of service, or GraphQL authorization and CSRF attacks; defenders should treat a GitLab compromise as a potential software supply-chain incident.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Scanning for vulnerable GitLab servers reportedly began on September 11, with exploitation following within hours of disclosure. The flaw could allow an unauthenticated attacker to read arbitrary files through traversal payloads in repository-commit API requests.
CISA reportedly added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after the GitLab repository commits API flaw was found to be actively exploited.
GitLab reportedly issued out-of-band updates for CVE-2026-85706, a CVSS 10.0 unauthenticated path-traversal flaw in the repository commits API, and CVE-2026-87719, an unsafe deserialization issue in GitLab EE Duo Chat. The updates also addressed six high-severity vulnerabilities; CVE-2026-85706 was fixed in versions 19.1.8, 19.2.6, and 19.3.2.
Honeypot systems reportedly observed exploitation attempts targeting the GitLab GraphQL vulnerability CVE-2026-19478.
WatchTowr reportedly reproduced CVE-2026-19478, demonstrating that improper validation of GraphQL directives could permit authorization bypass and anonymous mutations against public resources.
GitLab reportedly released out-of-band fixes for CVE-2026-19478, an unauthenticated GraphQL authorization-bypass flaw, and CVE-2026-19650, a GraphQL CSRF vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.