CISA: Hackers now exploit max severity GitLab flaw in attacks

CISA: Hackers now exploit max severity GitLab flaw in attacks
CISA warned that attackers are actively exploiting a maximum-severity GitLab flaw, CVE-2026-85706, which can let unauthenticated users read credentials and other sensitive data from vulnerable servers. GitLab has released fixes and CISA added the issue to its actively exploited catalog, urging organizations to patch immediately and hunt for signs of probing on affected systems. #GitLab #CVE-2026-85706 #CISA #watchTowr

Keypoints

  • CISA says hackers are exploiting the GitLab vulnerability CVE-2026-85706.
  • The flaw can expose credentials, secrets, and other sensitive information.
  • GitLab patched the issue in CE and EE versions 19.3.2, 19.2.6, and 19.1.
  • watchTowr reported in-the-wild probing for unpatched GitLab servers.
  • CISA added the flaw to its actively exploited catalog and urged immediate remediation.

Read More: https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/