Urgent.News

What's breaking now, across thousands of outlets.

Tech

CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately

A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.

CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical GitLab vulnerability, CVE‑2026‑85706, which is being actively exploited in the wild. This flaw, classified as critical severity with a score of 10/10, allows attackers to read sensitive files via the commits API without requiring authentication.

The issue stems from missing authentication enforcement and improper path confinement in the repository commits API. GitLab has released patches for Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1, but agencies have been given only three days to update their systems. WatchTower Intel reported observing probes for this latest critical GitLab Path Traversal vulnerability, suggesting that the exploitation window may be imminent.

Security experts advise defenders to monitor log files for HTTP POST requests targeting specific URI patterns containing file.path parameters to identify potential exploitation attempts.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at techradar.com →

More in Tech

More from Monday 14 September →