Critical GitLab Flaw Actively Exploited to Steal Server Secrets
Want more insights like this?
A maximum-severity GitLab vulnerability (CVE-2026-85706, CVSS 10.0 Critical) was being actively exploited within a day of its September 10 disclosure. The flaw lets unauthenticated attackers read arbitrary files from self-managed GitLab CE/EE servers — including credentials, CI/CD secrets, and SSH configurations — on any instance hosting at least one public project.
watchTowr saw probing on September 11 escalate the same day to full file exfiltration, and public proof-of-concept code is now circulating. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 11, giving federal agencies until September 14 to patch.
Self-managed instances on 19.1 through 19.3 should update to 19.1.8, 19.2.6, or 19.3.2; anyone on 18.7 through 19.0 should check GitLab's advisory for their branch. If patching isn't possible, remove all public project access now, then review repository commits API logs for unauthenticated requests.
Source: Dark Reading