Skip to content
See the World Through ScienceA project of ALLATRA

U.S. Cyber Agency Says a GitLab Flaw Is Being Exploited Now

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Screenshot of the GitLab web interface showing a project page with a sidebar menu and a list of repository files and folders.
The GitLab web interface, showing a project's file and folder listing in version 14.3 in August 2021. CISA's catalog entry concerns a path traversal flaw in GitLab Community Edition and Enterprise Edition."GitLab running 14.3.0-pre (2021-08)" by İsmail Arılık, via wikimedia, CC-BY-SA-4.0 · CC-BY-SA-4.0

The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in GitLab to its Known Exploited Vulnerabilities catalog on Sept. 11, 2026, saying the addition is based on evidence that the flaw is already being exploited.

That catalog sets what U.S. federal civilian agencies must fix first, so the listing creates a remediation obligation for any of them running the software. CISA encourages every other organization to do the same.

The flaw is tracked as CVE-2026-85706 and affects GitLab Community Edition and Enterprise Edition, the versions an organization installs on its own servers. The alert calls it a path traversal vulnerability, a class of flaw in which a program can be steered to files outside the area it is supposed to reach. That type of flaw is a frequent way in for attackers and a significant risk to federal systems, according to the alert.

The obligation itself comes from Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk," which CISA describes as requiring Federal Civilian Executive Branch agencies to prioritize rapid remediation of catalog-listed flaws on publicly exposed systems that would give an attacker total control, while deferring lower-risk work. The directive also sets out when an agency has to check whether its systems were compromised before the patch was applied.

CISA said it will keep adding vulnerabilities that meet its criteria. An entry needs a CVE identifier, evidence of exploitation, and clear guidance on how to fix the flaw.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

U.S. Cyber Agency Says a GitLab Flaw Is Being Exploited Now

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.