CISA: Hackers now exploit max severity GitLab flaw in attacks
Key Points:
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are actively exploiting a critical GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to access sensitive data on vulnerable servers.
- This flaw affects GitLab's repository commits API due to missing authentication enforcement and improper path confinement, impacting many users including over 50% of Fortune 100 companies.
- GitLab released patches for Community Edition and Enterprise Edition versions 19.3.2, 19.2.6, and 19.1, urging immediate updates, while cybersecurity firm watchTowr reported active probing of unpatched servers shortly after the fix.
- CISA has added the vulnerability to its catalog of actively exploited flaws and mandated federal agencies to secure their systems within three days under Binding Operational Directive 26-04, recommending all organizations prioritize patching.
- Earlier in January, GitLab also addressed a high-severity two-factor authentication bypass vulnerability, highlighting ongoing security challenges for the platform.