Urgent.News

What's breaking now, across thousands of outlets.

Tech

Sizing Self-Managed GitLab Exposure After CVE-2026-85706

Sizing Self-Managed GitLab Exposure After CVE-2026-85706 CVE-2026-85706 is an unauthenticated arbitrary file read in GitLab's repository commits API with a CVSS 3.1 score of 10.0. The fix shipped on 10 September 2026 in 19.3.2, 19.2.6 and 19.1.8, and CISA added the flaw to the Known Exploited Vulnerabilities catalog the following day. For anyone responsible for a self-managed instance, the…

GitLab self-managed instances are vulnerable to an unauthenticated arbitrary file read vulnerability (CVE-2026-85706) with a high severity CVSS 3.1 score of 10.0. The fix was released on 10 September 2026 for specific versions 19.3.2, 19.2.6 and 19.1.8. There are 1,262,273 matches of GitLab fingerprint in IPv4 devices and 52,074 matches in web datasets according to a ZoomEye query performed on 19 September 2026.

This measurement provides an estimate of reachable instances, not the exact count of vulnerable instances. Self-managed GitLab instances, especially those hosting credentials, can provide access to sensitive data and systems. The measurement helps prioritize response efforts by identifying exposed instances for patching and credential review.

Inventorying self-managed GitLab instances, verifying versions, upgrading to patched versions, restricting public reachability if upgrade is not immediate, and separately reviewing credentials are recommended actions.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Your README Is Lying to New Contributors

Your README Is Lying to New Contributors Here's an experiment: pick five repos you starred in the last year. Clone one. Follow the README's setup instructions exactly. I'll wait.

More from Saturday 19 September →