β― full post (808 more characters) β― show less
π¨ GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. β The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
β’ GitLab 18.7 through versions before 19.1.8 β’ GitLab 19.2 through versions before 19.2.6 β’ GitLab 19.3 through versions before 19.3.2 β GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow. β Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
π¨ GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. β The flaw allows an unauthenticated attack