GitLab urged users to immediately patch a maximum-severity path traversal flaw, CVE-2026-85706, that could let unauthenticated attackers read arbitrary data from vulnerable servers under certain conditions. The company also fixed CVE-2026-87719 in GitLab EE, while watchTowr reported early probing activity against exposed GitLab systems and warned defenders to check logs for suspicious API requests. #GitLab #CVE-2026-85706 #CVE-2026-87719 #watchTowr
Keypoints
- GitLab patched CVE-2026-85706, a maximum-severity path traversal vulnerability.
- The flaw can expose credentials, secrets, and sensitive data from affected servers.
- watchTowr observed in-the-wild probing for unpatched GitLab instances.
- GitLab also fixed CVE-2026-87719, an insecure deserialization issue in GraphQL subscriptions.
- Admins were told to upgrade GitLab CE and EE immediately to the latest fixed versions.