GitLab has patched CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API that is already seeing in-the-wild probing and could let unauthenticated attackers read arbitrary files from affected servers. The company also fixed CVE-2026-87719, a critical insecure deserialization issue in GitLab EE, and urged exposed self-managed instances to patch immediately or restrict public access. #GitLab #CVE-2026-85706 #CVE-2026-87719 #watchTowr
Keypoints
- GitLab released fixes for multiple security flaws in Community Edition and Enterprise Edition.
- CVE-2026-85706 is a critical path traversal bug in the repository commits API.
- The flaw can allow unauthenticated attackers to read arbitrary files from GitLab servers.
- watchTowr reported active probes against the vulnerability within hours of disclosure.
- GitLab also patched CVE-2026-87719, an insecure deserialization issue affecting GitLab EE.
Read More: https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html