Skip to content
GitLab's critical flaw is already drawing internet-wide probes

GitLab's critical flaw is already drawing internet-wide probes

Cyberscoop September 11, 2026

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws.

The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted.

The more serious of the two flaws, tracked as CVE-2026-85706 , sits in the interface that handles repository commits. GitLab said that under certain conditions an attacker could read any file on the server, because the code failed to confine file paths properly and did not enforce authentication. An attacker does not need an account nor credentials to take advantage of the flaw. The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches. GitLab assigned it a CVSS score of 10.0, the top of the scale used across the industry.

The second flaw, CVE-2026-87719 , affects only GitLab’s Enterprise Edition. The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced feature, which would return the settings and passwords being held. It affects releases from 18.3 onward and carries a CVSS score of 9.9.

WatchTowr Labs wrote in a post Friday that it was already watching probes against the path traversal flaw, which it said an attacker can trigger in one HTTP request. The firm said organizations running self-hosted GitLab servers reachable from the open internet face the greatest risk, and pointed defenders toward their logs, suggesting they look for POST requests to addresses under /api/v4/projects/{id}/repository/commits/ that carry a file.path parameter.

Drawing on earlier GitLab flaws, the firm said broad, untargeted attacks tend to follow soon after a patch appears.

“Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” the post read.

Despite the warning, the Cybersecurity and Infrastructure Security Agency (CISA) had not added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) list as of Friday afternoon.

You can find more information the vulnerabilities on GitLab’s website .

What the Section 702 lapse means for cybersecurity

AI-adaptable security platforms are critical for autonomous decision-making

Defending in the middle of the vulnpocalypse

The Vulnpocalypse arrived early

FTC rescinds policy requiring health apps to notify customers after a breach

Lawmakers call on Commerce to sanction hackers-for-hire

FBI cyber chief worries private sector not sharing enough cyber threat information

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

European parliament members call for slowdown of Serbia’s EU entry over spyware use

The G7 tells industry to hurry up and prep for post-quantum encryption

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

Chinese espionage groups swarm to exploit triple-link chain of zero-days

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Russian national extradited to US for alleged involvement in bank-account takeover scheme

Attackers exploit zero-days in consistently besieged SonicWall product

Wyden seeks upgraded NSA security guidance on commercial VPN use

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities