CISA Adds 2 GitLab Flaws to KEV List as CVSS 10.0 Bug Draws Internet Probes
Updated
Updated · CyberScoop · Sep 11
CISA Adds 2 GitLab Flaws to KEV List as CVSS 10.0 Bug Draws Internet Probes
3 articles · Updated · CyberScoop · Sep 11
Summary
CISA on Friday added two GitLab vulnerabilities to its Known Exploited Vulnerabilities list after GitLab issued emergency patches for self-managed Community and Enterprise editions.
CVE-2026-85706 carries a 10.0 CVSS score and lets an unauthenticated attacker read any file on a server via the repository commits interface, affecting releases from 18.7 through unpatched 19.3 builds.
WatchTowr Labs said it is already seeing probes for that path-traversal bug, which it said can be triggered in a single HTTP request against internet-exposed self-hosted GitLab servers.
The second flaw, CVE-2026-87719, scores 9.9 and affects Enterprise Edition from 18.3 onward, allowing a logged-in Duo Chat user to expose Advanced Search settings and stored passwords.
GitLab said its hosted service already runs fixed code and Dedicated customers are unaffected, but warned self-managed users to upgrade quickly as broad exploitation often follows public patches.