Security firm WatchTowr observed in-the-wild exploitation of CVE-2026-85706, a maximum-severity (CVSS 10) path-traversal vulnerability in GitLab Community and Enterprise Edition, just one day after GitLab released a patch, SecurityWeek reported. The flaw allows unauthenticated attackers to read arbitrary files from an affected server.
The same GitLab release also patched a second critical vulnerability, CVE-2026-87719, an insecure-deserialization flaw in GitLab’s GraphQL implementation.
Why it matters: A one-day gap between patch release and confirmed exploitation leaves almost no window for organizations to apply updates before attackers act, underscoring why source-code and DevOps infrastructure — not just perimeter network gear — needs to be included in any organization’s emergency-patching runbook.
Source: SecurityWeek, September 11, 2026.

Leave a Reply