INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GitLab CVE-2026-85706 Exploit Within 24 Hours

| 2026-09-14 10:00 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalog, a critical list of vulnerabilities that can compromise the security of software systems. This particular vulnerability is described as an "improper limitation of a pathname to a restricted directory" or "path traversal" flaw, which allows attackers to access arbitrary files on affected systems. The issue was first reported in September 2026 and has been under active exploitation for approximately 24 hours. CISA recommends that customers identify potential exploitation attempts by monitoring log files for HTTP POST requests containing "[IOC HIDDEN • LOGIN REQUIRED]" parameters and patch the vulnerability as soon as possible, with a deadline of September 15.
Technical Mitigations AI-generated
* Implement a secure authentication and authorization mechanism to ensure only authorized users can access sensitive data, such as SSH keys, database credentials, and deploy tokens. * Regularly monitor log files for suspicious HTTP POST requests to "/api/v4/projects/{id}/repository/commits/" URIs containing "<a href="/auth/login?next=/detail/vvcmlKABGvYhsJJTQUrp" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>" parameters, and take immediate action if potential exploitation attempts are detected. * Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and block in-the-wild probes of the GitLab path traversal vulnerability CVE-2026-85706. * Implement rate limiting on HTTP requests to "/api/v4/projects/{id}/repository/commits/" URIs containing "<a href="/auth/login?next=/detail/vvcmlKABGvYhsJJTQUrp" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>" parameters, to prevent attackers from exploiting the vulnerability by making multiple requests within a short time frame.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

fi•••••.path
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-85706CVE-2026-85706 CVE-2021-39935CVE-2021-39935 CVE-2021-22175CVE-2021-22175 CVE-2026-87719CVE-2026-87719 CVE-2023-2825CVE-2023-2825 CVE-2026-19478CVE-2026-19478
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎at least 2007
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours.
attribution CISA
attribution FBI
‎November 2021
Threat actors exploited CVE-2021-22175 and CVE-2021-39935 vulnerabilities in GitLab within 24 hours.
vulnerability CVE-2021-22175
vulnerability CVE-2021-39935
‎May 2023
Threat actors exploited CVE-2023-2825 in GitLab within 24 hours.
vulnerability CVE-2023-2825
‎September 10
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours.
‎September 10, 2026
Threat actors exploited the GitLab CVE-2026-85706 vulnerability within 24 hours.
organisation CVE-2026-85706
organisation API
vulnerability CVSS 10.0
‎2026/09/10
Threat actors exploited a previously unknown vulnerability in GitLab's GraphQL subscription serializer.
vulnerability CVE-2026-87719
‎September 11
Threat actors used a known vulnerability in GitLab to exploit CVE-2026-85706 within 24 hours.
organisation Cybersecurity
organisation WatchTowr
vulnerability CVE-2026-85706
organisation Update
‎Sep 11, 2026
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours.
‎September 11, 2026
Threat actors exploited CVE-2026-85706 in all versions of GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.7 before 19.1.8 to 19.3 before 19.3.2 within 24 hours.
infrastructure 18.7
infrastructure 19.1.8
infrastructure 19.2
infrastructure 19.2.6
infrastructure 19.3
infrastructure 19.3.2
organisation GitLab Community Edition (CE
organisation UTC
‎September 13, 2026
CVE-2026-85706, a CVSS 10.0 GitLab path traversal vulnerability, was exploited within 24 hours of its disclosure by threat actors targeting affected systems via one HTTP request with no authentication and full file read access.
vulnerability CVE-2026-85706
organisation GitLab
vulnerability CVSS 10.0
organisation CVSS
general_metric 24 Hours
‎2026/09/14
GitLab CVE-2026-85706 Exploit Within 24 Hours.
organisation CVE-2026-85706
organisation Intel
organisation SecurityAffairs
organisation API
organisation Unauthenticated
infrastructure 18.7
infrastructure 19.1.8
infrastructure 19.2
infrastructure 19.2.6
infrastructure 19.3
infrastructure 19.3.2
organisation GitLab CE/EE
organisation CVSS
infrastructure 9.9
organisation GitLab Community Edition (CE
infrastructure 19.1
organisation HackerOne
organisation POST
organisation Hackers Exploit Maximum Severity
organisation GitLab
organisation Vulnerability / Web Security
organisation Shutterstock.com
financial 04 BOD
organisation Duo Chat
organisation Advanced Search
organisation CVE-2026
organisation CVE-2023-2825
organisation SSH
organisation CI
organisation GitLab.com
organisation Airbus
organisation T-Mobile
organisation Lockheed
organisation Goldman Sachs
organisation UBS
victims 30 registered users
organisation NFL
organisation CHANEL
‎September 15
Threat actors exploited CVE-2026-85706 in GitLab within 24 hours, targeting civilian federal agencies with a deadline of September 15.
attribution KEV
Tactical Metrics
Metrics
infrastructure
‎18.7
Software Version
Metrics
infrastructure
‎19.1.8
Software Version
Metrics
infrastructure
‎19.2
Software Version
Metrics
infrastructure
‎19.2.6
Software Version
Metrics
infrastructure
‎19.3
Software Version
Metrics
infrastructure
‎19.3.2
Software Version
Metrics
financial
4
Bod
Metrics
infrastructure
‎9.9
Software Version
Metrics
infrastructure
‎19.1
Software Version
Metrics
victims
30,000,000
Registered Users
Intelligence Sources