Self-managed GitLab flaw reportedly exploited within a day of patch
A user’s thread says CVE-2026-85706 has a CVSS severity score of 10.0 and lets attackers read arbitrary server files without logging in.
TLDR
A user describes CVE-2026-85706 as a path-traversal flaw in self-managed GitLab that allows arbitrary server files to be read with a single unauthenticated HTTP request. The thread says it was patched on September 10, 2026, with exploitation confirmed by September 11—the same day CISA added it to its Known Exploited Vulnerabilities list.
Combined views
10
1 Source, first seen ago