GitLab Community Edition (CE) and Enterprise Edition (EE) updates address seven vulnerabilities, including the critical path-traversal flaw CVE-2026-85706 and two critical CI/CD code-execution vulnerabilities, CVE-2026-89078 and CVE-2026-93577. CVE-2026-85706 has a CVSS score of 10.0 and allows an unauthenticated remote attacker to read arbitrary files through the repository commits API because of improper path confinement and missing authentication enforcement. FortiGuard reported exploitation attempts across multiple countries and sectors, while CISA added the flaw to its Known Exploited Vulnerabilities catalog.
The two CVSS 9.9 CI/CD flaws can allow an authenticated user to execute arbitrary code on the GitLab server under certain conditions using specially crafted regular expressions in CI/CD configuration. Self-managed GitLab administrators should upgrade immediately: versions 19.2 should move to 19.2.7 or later, 19.3 to 19.3.3 or later, and 19.4 to 19.4.1 or later; earlier fixes for CVE-2026-85706 were released in 19.1.8, 19.2.6, and 19.3.2. Organizations should also review repository commits API logs for suspicious requests, particularly attempts to retrieve configuration or credential files.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog.
GitLab released versions 19.1.8, 19.2.6, and 19.3.2 to remediate CVE-2026-85706, a CVSS 10.0 unauthenticated path-traversal vulnerability in the repository commits API that could expose arbitrary files.
CERT-PY identified CVE-2026-89078 and CVE-2026-93577 as CVSS 9.9 GitLab CE/EE flaws. An authenticated user could submit specially crafted regular expressions through CI/CD configurations to achieve arbitrary code execution on the GitLab server under certain conditions.
GitLab released security updates addressing seven GitLab CE/EE vulnerabilities, including two critical and one high-severity issue, with information-disclosure and remote-code-execution impact. Affected versions include 19.2 releases before 19.2.7, 19.3 releases before 19.3.3, 19.4 releases before 19.4.1, and certain versions dating back to 13.11.
FortiGuard Labs observed attacks targeting CVE-2026-85706 across multiple countries and sectors, including targeting in Italy, Indonesia, Belarus, South Korea, and Germany. Public exploit and proof-of-concept material had also emerged.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourceacn.gov.it
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcecsirt.bj
Open sourcemeetcyber.net
Open sourcefortiguard.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.