Back Securityweek GitLab Vulnerability Exploited One Day After Disclosure
Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns.
Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server.
All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
On Friday, one day after GitLab announced patches for the security weakness, WatchTowr observed the first in-the-wild exploitation attempts targeting it.
“WatchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,” the company said .
“This is the second instance of a critical-severity GitLab vulnerability in recent weeks, following the GraphQL code injection (CVE-2026-19478) that was almost immediately actively exploited ,” Jake Knott, head of threat intelligence at WatchTowr, said.
According to WatchTowr, mass exploitation of the vulnerability is likely to follow shortly.
“Defenders should hunt through log files for HTTP POST requests to ‘/api/v4/projects/{id}/repository/commits/’ URIs containing ‘file.path’ parameters to identify potential exploitation attempts,” the company noted.
Self-hosted GitLab instances should be upgraded as soon as possible, as the fresh patches resolve 17 other vulnerabilities, including another critical-severity bug.
The critical flaw, tracked as CVE-2026-87719 (CVSS score of 9.9/10), is an insecure deserialization issue in the GraphQL subscription serializer that could allow attackers to access “Advanced instance configurations and sensitive credentials”.
GitLab CE/EE versions 19.1.8, 19.2.6, and 19.3.2 also resolve six high-severity security defects that could allow attackers to achieve remote code execution, access protected CI/CD variables, mount XSS attacks, and cause denial-of-service conditions.
“The appeal to attackers of GitLab is obvious, as unauthorized access allows an attacker to gain access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines, gaining access to or poisoning anything downstream of it, which, as we’ve seen throughout this year, has been a favorite of attackers,” Knott added.
Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Related: Check Point Patches Critical VPN Vulnerabilities
Related: PaperCut Flaws Exploited in AI-Powered Attacks
Related: Critical NetScaler Vulnerability Exploited in Attacks
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
PaperCut Flaws Exploited in AI-Powered Attacks
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.
Critical NetScaler Vulnerability Exploited in Attacks
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
Android’s September 2026 Updates Patch 180 Vulnerabilities
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
