U.S. Cyber Agency Says a GitLab Flaw Is Being Exploited Now

The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in GitLab to its Known Exploited Vulnerabilities catalog on Sept. 11, 2026, saying the addition is based on evidence that the flaw is already being exploited.
That catalog sets what U.S. federal civilian agencies must fix first, so the listing creates a remediation obligation for any of them running the software. CISA encourages every other organization to do the same.
The flaw is tracked as CVE-2026-85706 and affects GitLab Community Edition and Enterprise Edition, the versions an organization installs on its own servers. The alert calls it a path traversal vulnerability, a class of flaw in which a program can be steered to files outside the area it is supposed to reach. That type of flaw is a frequent way in for attackers and a significant risk to federal systems, according to the alert.
The obligation itself comes from Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk," which CISA describes as requiring Federal Civilian Executive Branch agencies to prioritize rapid remediation of catalog-listed flaws on publicly exposed systems that would give an attacker total control, while deferring lower-risk work. The directive also sets out when an agency has to check whether its systems were compromised before the patch was applied.
CISA said it will keep adding vulnerabilities that meet its criteria. An entry needs a CVE identifier, evidence of exploitation, and clear guidance on how to fix the flaw.
