Dark Web Informer :verified_paw: on Nostr: 🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure Threat ...
🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
â €
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2
â €
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
â €
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
Published at
2026-09-11 17:24:17 GMTEvent JSON
{
"id": "60193b8fecf09f9722fa13bea957f30c8e4dedd5aedd578fda5d88ff007d01bf",
"pubkey": "3602e3a41b34946d81c007fcf5ae0daae25997b4e04b107e82e56a090c0d9b81",
"created_at": 1789147457,
"kind": 1,
"tags": [
[
"imeta",
"url https://media.infosec.exchange/infosec.exchange/media_attachments/files/117/253/567/686/568/981/original/27ab2c516a268803.webp",
"m image/webp",
"dim 1200x675",
"blurhash UJ9j7@#RM{KPa#a}fQjs0zKPxuwHs:oJfQWq"
],
[
"proxy",
"https://infosec.exchange/users/DarkWebInformer/statuses/117253567771400768",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure\n\nThreat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.\n⠀\nThe flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.\n\nAffected versions include:\n\n• GitLab 18.7 through versions before 19.1.8\n• GitLab 19.2 through versions before 19.2.6\n• GitLab 19.3 through versions before 19.3.2\n⠀\nGitLab disclosed and patched the vulnerability on September 10.\n\nJust one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.\n⠀\nAdministrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.\n\nGitLab.com is already patched.\n\nSource: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/\n\nhttps://media.infosec.exchange/infosec.exchange/media_attachments/files/117/253/567/686/568/981/original/27ab2c516a268803.webp",
"sig": "f2185e4a902030cc4fe6d98fa473c0c00ba95ff02afe672cdf142e3e11fa415fd975dcb1dfca5f0b88b7ffa25f0b8d9bc871c3576db8222e1cc4a75f646b194f"
}