CISA Warns: Critical GitLab Vulnerability Exploited in Cyberattacks
U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms threat groups are actively exploiting a critical GitLab vulnerability, urging immediate patching to prevent data breaches.
CISA Confirmation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat groups are actively exploiting a critical vulnerability in the GitLab DevSecOps platform.
Vulnerability Details
This flaw, designated CVE-2026-85706, affects the repository commits API and allows unauthorized access to sensitive data through improper authentication mechanisms and path confinement issues.
Patch Information
GitLab addressed the issue in versions 19.3.2, 19.2.6, and 19.1 of its Community Edition and Enterprise Edition, releasing patches on Thursday. The company emphasized the urgency of applying these updates to prevent exploitation.
WatchTowr Observation
watchTowr Intel reported that adversaries are scanning networks for systems vulnerable to CVE-2026-85706, which facilitates arbitrary file access via a single HTTP request.
The firm warned that the window for widespread exploitation is narrowing, given the frequency of similar vulnerabilities in GitLab’s history.
CISA’s BOD 26-04
CISA incorporated the vulnerability into its catalog of actively exploited flaws, triggering Binding Operational Directive (BOD) 26-04. This directive mandates federal agencies to remediate the issue within three days.
Previous Vulnerabilities
This incident follows GitLab’s recent resolution of a high-severity two-factor authentication bypass flaw in January. Since November 2021, CISA has identified four GitLab vulnerabilities as actively exploited, including CVE-2021-22175 and CVE-2021-39935 in February 2026.
Conclusion
The latest development underscores the persistent threat landscape surrounding widely adopted development tools and the critical need for timely security updates.
