{
  "id": 7360375,
  "title": "CISA warns hackers are exploiting max severity GitLab flaw — urges all businesses to patch immediately",
  "url": "https://urgent.news/2026/09/14/cisa-warns-hackers-are-exploiting-max-severity-gitlab-flaw-urges-all",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-14T16:50:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/cisa-warns-hackers-are-exploiting-max-severity-gitlab-flaw-urges-all-businesses-to-patch-immediately"
  },
  "original_language": "en",
  "account": "The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical GitLab vulnerability, CVE‑2026‑85706, which is being actively exploited in the wild. This flaw, classified as critical severity with a score of 10/10, allows attackers to read sensitive files via the commits API without requiring authentication. The issue stems from missing authentication enforcement and improper path confinement in the repository commits API. GitLab has released patches for Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1, but agencies have been given only three days to update their systems. WatchTower Intel reported observing probes for this latest critical GitLab Path Traversal vulnerability, suggesting that the exploitation window may be imminent. Security experts advise defenders to monitor log files for HTTP POST requests targeting specific URI patterns containing file.path parameters to identify potential exploitation attempts.",
  "summary": "A 10/10 GitLab flaw was added to CISA's KEV, giving government agencies just three days to patch.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Perfect-10 GitLab bug under attack days after patch lands",
        "url": "https://urgent.news/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands",
        "published": "2026-09-14T14:30:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}