Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

GitLab Vulnerability Exploited One Day After Disclosure

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

GitLab

Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns.

Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server.

All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.

On Friday, one day after GitLab announced patches for the security weakness, WatchTowr observed the first in-the-wild exploitation attempts targeting it.

“WatchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,” the company said.

According to WatchTowr, mass exploitation of the vulnerability is likely to follow shortly.

Advertisement. Scroll to continue reading.

“Defenders should hunt through log files for HTTP POST requests to ‘/api/v4/projects/{id}/repository/commits/’ URIs containing ‘file.path’ parameters to identify potential exploitation attempts,” the company noted.

Self-hosted GitLab instances should be upgraded as soon as possible, as the fresh patches resolve 17 other vulnerabilities, including another critical-severity bug.

The critical flaw, tracked as CVE-2026-87719 (CVSS score of 9.9/10), is an insecure deserialization issue in the GraphQL subscription serializer that could allow attackers to access “Advanced Search instance configurations and sensitive credentials”.

GitLab CE/EE versions 19.1.8, 19.2.6, and 19.3.2 also resolve six high-severity security defects that could allow attackers to achieve remote code execution, access protected CI/CD variables, mount XSS attacks, and cause denial-of-service conditions.

Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Related: Check Point Patches Critical VPN Vulnerabilities

Related: PaperCut Flaws Exploited in AI-Powered Attacks

Related: Critical NetScaler Vulnerability Exploited in Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.