Key Facts
CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities Catalog on September 11, identifying active exploitation of a GitLab CE/EE path-traversal issue.
Technical Details
GitLab says the repository commits API issue can allow unauthenticated reading of arbitrary files. BleepingComputer reports that watchTowr observed in-the-wild probing and recommends reviewing relevant API request logs.
Impact & Mitigation
Upgrade self-managed GitLab CE/EE to fixed releases 19.3.2, 19.2.6, or 19.1.8 as applicable, per GitLab’s patch release. Prioritize exposed instances and investigate for suspicious requests to the repository commits API.
