CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.
GitLab urged users to immediately patch a maximum-severity path traversal vulnerability (CVE-2026-85706) in its repository commits API that allows unauthenticated attackers to read arbitrary data from vulnerable servers. Cybersecurity firm watchTowr reported that attackers are already probing for unpatched GitLab instances. The company also patched a second critical deserialization vulnerability (CVE-2026-87719) affecting GitLab Enterprise Edition.
GitLab released patches for CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API allowing unauthenticated users to read arbitrary files. The vulnerability has already been probed in-the-wild within hours of disclosure, affecting multiple GitLab Community and Enterprise Edition versions. A second critical flaw, CVE-2026-87719, an insecure deserialization bug in GitLab EE, was also patched.