A Critical Vulnerability in GitLab’s DevSecOps Platform is Being Exploited in Attacks, CISA Warns
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are taking advantage of a maximum-severity vulnerability in GitLab’s popular DevSecOps platform. The security flaw, tracked as CVE-2026-85706, allows attackers to read sensitive information from vulnerable servers without authentication.
GitLab’s platform is used by over 50% of Fortune 100 companies and has more than 30 million registered users worldwide. The vulnerability stems from a combination of missing authentication enforcement and improper path confinement in the repository commits API. This means that an unauthenticated attacker can exploit it to access credentials, secrets, and other sensitive information.
The security issue was fixed by GitLab in versions 19.3.2, 19.2.6, and 19.1 of its Community Edition (CE) and Enterprise Edition (EE). The company urged users to patch their systems immediately, but it appears that hackers are already taking advantage of the flaw. WatchTowr, a cybersecurity firm, reported that attackers were probing the internet for GitLab servers that had not been patched against the vulnerability.
CISA has added CVE-2026-85706 to its catalog of actively exploited flaws and is urging all network defenders to patch their devices as soon as possible. This warning applies not only to government agencies but also to organizations in the private sector, which are encouraged to prioritize remediation of critical vulnerabilities like this one.
This is not the first time that a GitLab vulnerability has been exploited by hackers. In January, the company patched a high-severity two-factor authentication bypass flaw that allowed attackers to circumvent two-factor authentication. Since November 2021, CISA has tagged four GitLab vulnerabilities as actively exploited, highlighting the need for organizations to stay on top of security patches and updates.
In light of this warning, it’s essential for users of GitLab’s DevSecOps platform to take immediate action. This includes patching their systems against CVE-2026-85706 and ensuring that all dependencies are up-to-date. It’s also crucial to monitor network activity and log files for signs of potential exploitation attempts.
By taking these steps, organizations can reduce the risk of falling victim to attacks exploiting this critical vulnerability. Remember that timely patching and monitoring can go a long way in preventing security breaches and protecting sensitive information.
Source: Bleeping Computer — 2026-09-14