CISA has warned that hackers are actively exploiting a maximum-severity GitLab vulnerability. The flaw allows unauthenticated attackers to read credentials, secrets and other sensitive files from vulnerable servers.
Tracked as CVE-2026-85706, the security issue affects GitLab Community Edition and Enterprise Edition. Administrators should install the available updates immediately and inspect their logs for signs of exploitation.
GitLab Flaw Exposes Sensitive Server Files
CVE-2026-85706 combines missing authentication enforcement with improper path confinement in the repository commits API. As a result, remote attackers can exploit the weakness without signing in.
A successful attack allows hackers to read arbitrary files from an affected GitLab server through a single HTTP request. Those files may contain credentials, access tokens, configuration details and other confidential information.
GitLab’s DevSecOps platform has more than 30 million registered users worldwide. Moreover, over half of Fortune 100 companies reportedly use it. Therefore, widespread exploitation could affect many high-value corporate environments.
The vulnerability received the maximum possible severity rating. Its low attack complexity and lack of authentication requirements make exposed servers particularly attractive targets.
Attackers Probe Internet for Vulnerable Servers
GitLab addressed the flaw in Community Edition and Enterprise Edition versions 19.3.2, 19.2.6 and 19.1. The company also urged customers to update their installations immediately.
One day after the patches appeared, cybersecurity company watchTowr detected attackers scanning the internet for vulnerable GitLab servers. Researchers warned that indiscriminate exploitation would likely follow quickly.
GitLab had not officially marked the vulnerability as actively exploited at that point. However, the observed probing showed that attackers had already started searching for unpatched systems.
Defenders should examine their server logs for suspicious HTTP POST requests targeting the repository commits API. In particular, requests containing unusual file.path parameters may indicate an exploitation attempt.
CISA Adds Flaw to Exploited Vulnerability List
CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalogue on September 11. The agency’s decision confirms that attackers have used the GitLab vulnerability in real-world incidents.
Under Binding Operational Directive 26-04, US federal civilian agencies received three days to secure affected systems. The requirement applies specifically to federal organisations.
Nevertheless, CISA urged private companies and other network defenders to prioritise the update. The agency warned that vulnerabilities of this type frequently provide entry points for malicious actors.
Organisations should also assume that exposed secrets may have been compromised if attackers accessed a vulnerable server. Consequently, incident response may require rotating credentials and access tokens in addition to applying the patch.
GitLab Faces Continued Security Attention
The latest attacks follow several other serious security issues affecting GitLab. In January, the company patched a high-severity flaw that allowed attackers to bypass two-factor authentication when they knew a target’s account ID.
Since November 2021, CISA has identified four GitLab vulnerabilities as actively exploited. The agency added two older flaws, CVE-2021-22175 and CVE-2021-39935, to its catalogue in February 2026.
Administrators should update vulnerable GitLab installations without delay. In addition, they should review API logs, investigate suspicious file-access attempts and replace any secrets that attackers may have exposed.


0 responses to “Hackers Exploit Maximum-Severity GitLab Vulnerability”