GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
What happened
GitLab released patches for CVE-2026-85706, a path traversal flaw in the repository commits API that allows unauthenticated users to read arbitrary files from the server. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 11, 2026, after watchTowr reported active in-the-wild probes beginning that same day.
Why it ranks #1
GitLab patched CVE-2026-85706, an unauthenticated path traversal flaw, after CISA listed it in KEV following watchTowr’s report of active in-the-wild probes.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
What to do
Apply patches immediately or restrict public access for internet-exposed, self-managed GitLab instances.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited