Back to News
Cybersecurity

Critical GitLab Vulnerability Exploited Soon After Disclosure

GitLab's maximum-severity vulnerability CVE-2026-85706 has been actively probed by attackers shortly after its announcement, necessitating immediate action from organizations.

GitLab has recently patched several vulnerabilities, including a critical security flaw designated as CVE-2026-85706, which carries a maximum CVSS score of 10.0. This path traversal vulnerability in the repository commits API allows unauthenticated users to access and read arbitrary files on the GitLab server. The alarming speed at which this vulnerability has been exploited in the wild underscores the urgency for organizations using GitLab to apply patches and strengthen their security measures promptly.

For businesses, the implications are significant. The rapid exploitation of such vulnerabilities highlights the need for robust security protocols and timely updates in software management practices. Organizations must prioritize vulnerability management and ensure that they are prepared to respond quickly to disclosures, especially those with high CVSS scores. The incident serves as a stark reminder of the evolving threat landscape in cybersecurity, where attackers are quick to act on newly disclosed weaknesses, making it imperative for companies to adopt a proactive approach to their cybersecurity strategies.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html)*