CISA: Hackers now exploit max severity GitLab flaw in attacks
by Sergiu Gatlan
September 14, 2026
| Notes |
|---|
| CISA |
| GitLab |
| GitLab DevSecOps used by over 50% of Fortune 100 companies – 30m+ users worldwide |
| CVE-2026-85706 – missing authentication enforcement, improper path confinement |
| GitLab Community Edition |
| GitLab Enterprise Edition |
| affected versions: 19.3.2, 19.2.6, 19.1 |
| recommendation: patching |
| watchTowr |
| path traversal vulnerability |
| https://www.linkedin.com/posts/watchtowr-intel-is-already-observing-in-the-wild-share-7504127030326673408-E8qx/ |
| IoC: HTTP POST to ‘api/v4/projects/{id}/repository/commits’ URIs containing ‘file.path’ parameter |
| CISA KEV |
| Binding Operational Directive (BOD) 26-04 |
| https://www.bleepingcomputer.com/news/security/gitlab-warns-of-high-severity-2fa-bypass-denial-of-service-flaws/ |
| Since November 2021, CISA has added four GitLab vulnerabilities into the KEV catalog |
| CVE-2021-22175 |
| CVE-2021-39935 |