The record
Written from the 1 report below. Nothing here is unsourced.
- GitLab has released patches fixing a maximum-severity path traversal flaw (CVE-2026-85706, CVSS 10.0) in the repository commits API.
- The flaw allows an unauthenticated attacker to read arbitrary files, including configuration files holding credentials and secrets, when at least one public project exists on the server.
- Security firm watchTowr observed active probing of the flaw starting 06:00 UTC on September 11, 2026, and later confirmed successful exploitation and exfiltration of sensitive files.
- The U.S.
- Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog on September 11, 2026, giving federal agencies a deadline of September 14, 2026 to apply fixes.
- Organizations running internet-exposed self-managed GitLab instances must patch immediately to versions 19.3.2, 19.2.6, or 19.1.8, or the flaw could let attackers steal source code, CI/CD secrets, and poison build pipelines.
What to watch next
- Escalation from targeted probing to indiscriminate mass exploitation, which watchTowr warns may be near.
- Whether attackers use stolen log file credentials and SSH configurations to gain full access to GitLab hosts.
- Second critical GitLab bug CVE-2026-87719 (CVSS 9.9) in GitLab EE being exploited, after patches were issued alongside the main fix.
Who said what3
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Jake Knott
head of threat intelligence at watchTowr
3 quotes · 1 outlet
“This is the second instance of a critical severity GitLab vulnerability in recent weeks, following the previous GraphQL code injection (CVE-2026-19478) that was almost immediately actively exploited”
In the article
…probes since 06:00 UTC on September 11, 2026. The issue, it said, allows an external attacker to read log files and GitLab-specific configuration files to obtain credentials, secrets, and sensitive information. " This is the second instance of a critical severity GitLab vulnerability in recent weeks, following the previous GraphQL code injection (CVE-2026-19478) that was almost immediately actively exploited ," Jake Knott, head of threat intelligence at watchTowr, said in a statement shared with The Hacker News. "Exploitation requires just one requirement, at least one public project must exist." "The appeal to attackers of…
“Exploitation requires just one requirement, at least one public project must exist.”
In the article
…following the previous GraphQL code injection (CVE-2026-19478) that was almost immediately actively exploited," Jake Knott, head of threat intelligence at watchTowr, said in a statement shared with The Hacker News. " Exploitation requires just one requirement, at least one public project must exist. " "The appeal to attackers of GitLab is obvious, as unauthorized access allows an attacker to gain access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines, gaining access…
Coverage1
All filed from India
Named United States · GitLab · CISA · Jake Knott · watchTowr
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
