INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Maximum Severity GitLab Flaw Exploited in Attacks
| 2026-09-14 20:19 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent exploitation of a maximum-severity GitLab vulnerability has significant implications for organizations with self-managed instances. The CVE-2026-85706 flaw, disclosed last week and patched on September 10, allows unauthenticated individuals to read arbitrary files from the server. This could compromise sensitive information like passwords and CI/CD secrets, potentially granting attackers further access into downstream systems. Organizations are urged to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for Community Edition and Enterprise Editions. The vulnerability exists in both CE and EE, which organizations use to set up self-hosted instances within their environments. Threat actors could exploit this flaw by dumping config files with secrets and system SSH configurations, compromising sensitive information.
Technical Mitigations AI-generated
* Implement authentication and authorization: Ensure that all users have proper access controls, including authentication checks on repository commits API, to prevent unauthorized access to public projects.
* Regularly update GitLab instances: Update self-hosted GitLab instances to the latest versions (19.3.2, 19.2.6, or 19.1.8) for Community Edition and Enterprise Edition to ensure patching of CVE-2026-85706.
* Monitor access logs: Regularly review access logs on the repository commits API for suspicious or unauthenticated requests that suggest probing or exploitation activity.
* Use secure configuration options: Consider using secure configuration options, such as "public" projects, in GitLab to limit exposure and restrict access to sensitive areas of the platform.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fi•••••.path
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Cyclops BlinkCyclops Blink
CVE-2026-85706CVE-2026-85706
CVE-2026-87719CVE-2026-87719
CVE-2021-22175CVE-2021-22175
CVE-2021-39935CVE-2021-39935
CVE-2026-19478CVE-2026-19478
Target & Sectors
Global Scope
governmentgovernment
technologytechnology
Incident Timeline
November 2021
Threat actors exploited the CVE-2021-22175 and CVE-2021-39935 vulnerabilities in GitLab.
Click on any entity below to view its context and source!
vulnerability
CVE-2021-22175
Since November 2021, CISA has tagged four GitLab vulnerabilities as actively exploited, including two (
CVE-2021-22175
and
CVE-2021-39935
) in February this year.
vulnerability
CVE-2021-39935
Since November 2021, CISA has tagged four GitLab vulnerabilities as actively exploited, including two (
CVE-2021-22175
and
CVE-2021-39935
) in February this year.
2026/08/15
Attackers exploited CVE-2026-19478, a GraphQL code injection flaw.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-19478
Last month, attackers exploited
CVE-2026-19478
, a GraphQL code injection flaw, shortly after it was publicly disclosed.
2026/09/07
Threat actors are exploiting a maximum-severity vulnerability in GitLab that was disclosed last week.
Sept. 10
Threat actors exploited a path traversal flaw in GitLab's CVE-2026-85706 to gain unauthorized access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85706
CVE-2026-85706, which GitLab disclosed and patched on Sept. 10, is a
path traversal flaw
that allows unauthenticated individuals to read arbitrary files from the GitLab server.
organisation
GitLab
CVE-2026-85706, which GitLab disclosed and patched on Sept. 10, is a
path traversal flaw
that allows unauthenticated individuals to read arbitrary files from the GitLab server.
Sept. 11, 2026
Threat actors exploited a critical flaw in the GitLab software.
2026/09/14
Threat actors exploited a critical flaw in GitLab, targeting affected systems and requiring immediate patching or disabling.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85706
The Cybersecurity and Infrastructure Security Agency (CISA)
added CVE-2026-85706
to its Known Exploited Vulnerabilities catalog on Friday and required federal agencies to patch or disable their self-managed GitLab instances by today.
attribution
Known Exploited
The Cybersecurity and Infrastructure Security Agency (CISA)
added CVE-2026-85706
to its Known Exploited Vulnerabilities catalog on Friday and required federal agencies to patch or disable their self-managed GitLab instances by today.
tactic
T1588.006 - Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA)
added CVE-2026-85706
to its Known Exploited Vulnerabilities catalog on Friday and required federal agencies to patch or disable their self-managed GitLab instances by today.
general_metric
85706 CVE-2026
The Cybersecurity and Infrastructure Security Agency (CISA)
added CVE-2026-85706
to its Known Exploited Vulnerabilities catalog on Friday and required federal agencies to patch or disable their self-managed GitLab instances by today.
2026/09/14
GitLab exploited a critical flaw in its repository commits API, allowing attackers to read arbitrary files and gain access to sensitive information.
Click on any entity below to view its context and source!
organisation
CVE-2026
"The combination is, as you can imagine, potent, as it may allow threat actors the ability to extract passwords, connect to instances that allow password authentication, and gain access to the host under the right conditions."
Even though CVE-2026-85706 exploitation gives an attacker read-only access to a GitLab instance, the attacker could use that access to obtain sensitive information like credentials and CI/CD secrets; this could not only enable a full compromise of the GitLab instance but also grant the attacker further admission into an organization's development environment and other critical downstream systems.
organisation
CI
"The combination is, as you can imagine, potent, as it may allow threat actors the ability to extract passwords, connect to instances that allow password authentication, and gain access to the host under the right conditions."
Even though CVE-2026-85706 exploitation gives an attacker read-only access to a GitLab instance, the attacker could use that access to obtain sensitive information like credentials and CI/CD secrets; this could not only enable a full compromise of the GitLab instance but also grant the attacker further admission into an organization's development environment and other critical downstream systems.
organisation
WatchTowr
WatchTowr noted that CVE-2026-85706 is the second critical vulnerability in GitLab to be targeted recently.
organisation
API
The security flaw (tracked as
CVE-2026-85706
) stems from missing authentication enforcement and improper path confinement in the repository commits API, and unauthenticated attackers can exploit it to read credentials, secrets, and other sensitive information from vulnerable servers.
The vulnerability, which received a CVSS score of 10 out of 10, stems from improper path confinement and missing authentication checks in the platform's repository commits API, according to
GitLab's advisory
.
organisation
Intel
"watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,"
it warned
.
organisation
GitLab
Hackers now exploit max severity GitLab flaw in attacks.
GitLab’s critical flaw is already drawing internet-wide probes.
infrastructure
19.3.2
In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."
WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition.
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
infrastructure
19.2.6
In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."
WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition.
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
infrastructure
19.1.8
In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."
WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition.
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
organisation
GitLab Community Edition (CE
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
The vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE), which organizations use to set up self-hosted GitLab instances within their environments.
infrastructure
19.1
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
infrastructure
18.7
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
infrastructure
19.2
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
infrastructure
19.3
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
organisation
CVSS
The vulnerability, which received a CVSS score of 10 out of 10, stems from improper path confinement and missing authentication checks in the platform's repository commits API, according to
GitLab's advisory
.
GitLab assigned it a CVSS score of 10.0, the top of the scale used across the industry.
organisation
SSH
"Over the weekend, we also observed threat actors dumping config files for secrets along with system SSH configurations for the victim system," Knott says.
organisation
POST
The firm said organizations running self-hosted GitLab servers reachable from the open internet face the greatest risk, and pointed defenders toward their logs, suggesting they look for POST requests to addresses under /api/v4/projects/{id}/repository/commits/ that carry a file.path parameter.
financial
04 BOD
"While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
victims
30 registered users
GitLab's DevSecOps platform is used by over 50% of Fortune 100 companies and has over 30 million registered users worldwide.
victims
26 targets
Although BOD 26-04 targets only federal agencies, CISA encouraged all network defenders, including those in the private sector, to patch their devices as soon as possible against ongoing attacks.
organisation
GitLab’s Enterprise Edition
The second flaw,
CVE-2026-87719
, affects only GitLab’s Enterprise Edition.
infrastructure
18.3
It affects releases from 18.3 onward and carries a CVSS score of 9.9.
infrastructure
9.9
It affects releases from 18.3 onward and carries a CVSS score of 9.9.
organisation
Community Edition and Enterprise Edition
The company
patched the issues in new versions
of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible.
organisation
Duo Chat
The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature, which would return the settings and passwords being held.
organisation
Advanced Search
The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature, which would return the settings and passwords being held.
Tactical Metrics
Metrics
infrastructure
19.3.2
Software Version
Click for context!
In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."
WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition.
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
Metrics
infrastructure
19.2.6
Software Version
In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."
WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition.
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
Metrics
infrastructure
19.1.8
Software Version
In others, they might falsely assume that the project is still 'internal' if it's made public within their GitLab system."
WatchTowr urged GitLab customers to update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 for GitLab Community Edition and Enterprise Edition.
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
Metrics
infrastructure
19.1
Software Version
GitLab fixed this security issue in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 on Thursday, and urged users to patch their systems immediately.
Metrics
financial
4
Bod
"While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
Metrics
victims
30,000,000
Registered Users
GitLab's DevSecOps platform is used by over 50% of Fortune 100 companies and has over 30 million registered users worldwide.
Metrics
victims
26
Targets
Although BOD 26-04 targets only federal agencies, CISA encouraged all network defenders, including those in the private sector, to patch their devices as soon as possible against ongoing attacks.
Metrics
infrastructure
18.7
Software Version
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
Metrics
infrastructure
19.2
Software Version
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
Metrics
infrastructure
19.3
Software Version
The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
Metrics
infrastructure
18.3
Software Version
It affects releases from 18.3 onward and carries a CVSS score of 9.9.
Metrics
infrastructure
9.9
Software Version
It affects releases from 18.3 onward and carries a CVSS score of 9.9.
Intelligence Sources
Dark Reading
2026-09-14
BleepingComputer
2026-09-14
CISA: Hackers now exploit max severity GitLab flaw in attacks
BleepingComputer
CyberScoop
2026-09-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-15T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
GitLab
entity
9x
infrastructure
Software Version
19.3.2
version
8x
attribution
Attributing Entity
GitLab Exploitation Jeopardizes Supply Chains
authority
7x
timeline
Temporal Reference
2026/09/07
date
5x
vulnerability
Exploited CVE
CVE-2026-85706
cve
2x
vulnerability
CVSS Score
10
score
Contextual Telemetry
Context Block
14 METRICS
tactic
Cyber Operation Type
Exfiltration
tactic
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Cve-2026
85,706
cve-2026
malware
Malware Payload
Cyclops Blink
tool
general metric
Fraud Emails
1,000,000
fraud emails
industry
Targeted Sector
Government
sector
general metric
Bod
26
bod
general metric
19.2.6
19
19.2.6
financial
Bod
4
bod
general metric
%
50
%
general metric
Companies
100
companies
victims
Registered Users
30,000,000
registered users
victims
Targets
26
targets
general metric
Lines
19
lines
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.