GitLab, a platform for managing and delivering software, has a critical vulnerability that attackers are exploiting, according to the U.S. Cybersecurity and Infrastructure Security Agency. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on Sept. 11, 2026, and listed a Sept. 14 remediation deadline.
What is GitLab, and what can the flaw expose?
GitLab helps development teams manage code, build and test applications, and deploy software. Its documentation describes these functions as parts of the same development platform.
The flaw affects an interface for working with repository commits. Missing authentication checks and inadequate restrictions on file paths can allow someone who has not logged in to read files on a vulnerable server, according to CISA’s catalog entry.
Security firm watchTowr says that access can expose configuration files, credentials and other sensitive information. GitLab rates the vulnerability 10.0 on the CVSS severity scale.
What evidence is there of attacks?
CISA has classified the vulnerability as known to be exploited, while watchTowr separately reports observing probes for it. The company’s public warning describes attackers looking for vulnerable installations; it does not establish that every probed server was breached.
CISA’s entry lists use in ransomware campaigns as unknown. That leaves the nature and extent of the attacks unresolved in the agency’s record.
Which GitLab versions need updating?
The affected Community Edition and Enterprise Edition releases are 18.7 up to, but not including, 19.1.8; 19.2 before 19.2.6; and 19.3 before 19.3.2. GitLab released the fixes on Sept. 10 and urges immediate upgrades.
GitLab.com is patched, and GitLab Dedicated customers do not need to take action, according to the same advisory.
What should self-managed GitLab administrators do?
Administrators should patch exposed installations promptly or remove public access, watchTowr advises. The firm also recommends examining server logs for possible exploitation attempts.
GitLab has published three threat detections to help self-managed customers look for attempts to exploit this vulnerability.