Marthio Marthio
Technology

GitLab releases emergency patches for CVSS 10.0 flaw exploited by US authorities

GitLab issued urgent security updates on September 10 to fix a critical vulnerability now flagged as actively exploited by the US Cybersecurity and Infrastructure Security Agency.

GitLab released emergency security updates on September 10 to address two critical vulnerabilities, including CVE-2026-85706. The defect carries a CVSS score of 10.0 and affects GitLab Community Edition and Enterprise Edition versions 19.3.2, 19.2.6, and 19.1.8. Proper path confinement and missing authentication enforcement in the repository commits API allowed potential unauthorized file access under specific conditions. The US Cybersecurity and Infrastructure Security Agency listed CVE-2026-85706 on its Known Exploited Vulnerabilities catalogue on September 11, noting evidence of exploitation in the wild. The agency set a September 14 remediation deadline for organizations bound by operational requirements. GitLab urged administrators of self-managed installations to upgrade immediately, while users of GitLab.com did not require immediate action. Fixes apply broadly across deployment types unless advisories specify otherwise.

GitlabSoftware updateCve 2026 85706CybersecurityServer vulnerabilityRemote code executionSupply chain securityDevops platform