logo

GitLab’s critical flaw is already drawing internet-wide probes

ID: d66a24c2-cc41-5039-abed-87fe6627b402

STIX ID: report--d66a24c2-cc41-5039-abed-87fe6627b402

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

Author: Greg Otto

...
...

GitLab released emergency patches for two critical vulnerabilities—CVE-2026-85706 (unauthenticated path traversal allowing arbitrary file reads, CVSS 10.0) and CVE-2026-87719 (exposure of Advanced Search settings/passwords to certain logged-in users, CVSS 9.9). WatchTowr Labs reported internet-wide probes targeting the path traversal, and CISA added the issues to its Known Exploited Vulnerabilities list; self-hosted, internet-reachable GitLab instances should patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.