LIVE · cybersecurity feed
Live wire
CVE-2026-85706

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]

zeroday.news ·

GitLab has confirmed that a critical path traversal vulnerability, identified as CVE-2026-85706, is being actively exploited in the wild, with initial probes detected within 24 hours of its public disclosure. The flaw, which carries a CVSS score of 10.0, affects the repository commits API in GitLab Community Edition and Enterprise Edition.

The vulnerability allows an unauthenticated attacker to read arbitrary files on a vulnerable GitLab instance by sending a single, specially crafted HTTP request. This could expose highly sensitive information such as SSH keys, database credentials, deploy tokens, CI/CD variables, and other configuration data.

GitLab officially disclosed CVE-2026-85706 on September 10, 2026. By September 11, active exploitation attempts were already observed. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added this flaw to its Known Exploited Vulnerabilities catalog, urging immediate action from affected organizations.

The vulnerability impacts all GitLab Community Edition and Enterprise Edition versions from 18.7 prior to 19.1.8, 19.2 prior to 19.2.6, and 19.3 prior to 19.3.2. GitLab has released patches to address the issue. Organizations operating public-facing, self-hosted GitLab instances are strongly advised to apply these updates without delay or, as an alternative, to restrict public access to their instances.

Security researchers have noted that the rapid exploitation of CVE-2026-85706 mirrors previous GitLab path traversal vulnerabilities, such as CVE-2023-2825, which also saw active attacks shortly after disclosure. This pattern underscores the urgency for organizations to address such critical flaws immediately.

In addition to patching, defenders should examine their log files for HTTP POST requests directed to `/api/v4/projects/{id}/repository/commits/` URIs that include `file.path` parameters. The presence of such parameters in these requests can indicate an attempted or successful exploitation of the vulnerability.

Organizations that suspect compromise or have confirmed exploitation are advised to rotate any credentials that may have been exposed, including tokens, SSH keys, CI/CD variables, and cloud keys. This step is crucial to mitigate further risk following a potential data breach.

The same update cycle that addresses CVE-2026-85706 also patches CVE-2026-87719, an insecure deserialization flaw. This separate vulnerability could expose advanced search configurations and associated credentials, providing an additional incentive for organizations to upgrade their GitLab instances.

vulnerabilities in this storyCVE-2026-85706
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice