GitLab released a critical patch on September 10 for a maximum-severity path traversal flaw in the repository commits API, and U.S. authorities say it is already being exploited. The vulnerability, tracked as CVE-2026-85706, carries a CVSSv3.1 score of 10.0 and affects both Community Edition and Enterprise Edition.
According to GitLab, the bug combines improper path confinement with missing authentication enforcement, which could let an unauthenticated user read arbitrary files from an affected server under certain conditions. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11 based on evidence of active exploitation, and set a September 14 remediation deadline for Federal Civilian Executive Branch agencies. The entry also carries forensic triage requirements under Binding Operational Directive 26-04.
Fixes are available for self-managed instances in three release lines: 19.1.8, 19.2.6, and 19.3.2, covering all versions from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2 respectively. GitLab.com already runs a patched version, and GitLab Dedicated customers do not need to act, but every self-managed deployment type is affected, including Omnibus, source code, and Helm chart installations.
The updates include database migrations, so single-node installations will go down while those run; multi-node setups can use GitLab's zero-downtime upgrade procedure. Only 19.3.2 ships post-deployment migrations. Rapid7 recommends treating the fix as an emergency action outside normal patch cycles, and says organizations should look for signs of compromise even after upgrading because exploitation is confirmed.
The same release addresses 17 other vulnerabilities, among them CVE-2026-87719, a critical insecure deserialization flaw in GitLab EE rated 9.9. GitLab says an authenticated user with Duo Chat access could, under certain conditions, obtain Advanced Search instance configurations and sensitive credentials through a specially crafted GraphQL subscription argument. Only CVE-2026-85706 is known to be exploited in the wild at the time of publication.
The disclosure lands in a stretch of urgent patch cycles for widely deployed enterprise software. Earlier in September, SonicWall disclosed two SMA1000 vulnerabilities that the vendor said were being actively exploited and could be chained for unauthenticated remote code execution, while Microsoft's September Patch Tuesday put 999 vulnerabilities on the table, the most it has ever published in a single day. Researchers went public in April with a GitHub flaw, CVE-2026-3854, that had exposed repositories across tenants, and nearly two months after GitHub's March patches most Enterprise Server instances remained unpatched.
Rapid7 customers using Exposure Command, InsightVM, or Nexpose can check for exposure to CVE-2026-85706 through a vulnerability check in the September 15 content release. The advisory does not say whether any specific organization has been breached, only that exploitation has been observed.













