ThinkPatternGet the app
Story
TECHNOLOGY · SEP 14, 2026

CISA Orders Federal Agencies to Patch Critical GitLab Flaw

The Cybersecurity and Infrastructure Security Agency mandated federal agencies patch a critical GitLab vulnerability after hackers began exploiting the flaw to steal sensitive credentials.

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal civilian agencies to patch or cease using the GitLab DevSecOps platform by September 15. The mandate follows the discovery of a critical path traversal vulnerability, tracked as CVE-2026-85706, which CISA added to its known-exploited vulnerabilities catalog on September 11.

GitLab released patches on September 10 for its Community and Enterprise Editions (versions 19.3.2, 19.2.6, and 19.1.8) to address the flaw. The vulnerability carries a maximum CVSS score of 10.0 and allows unauthenticated external attackers to read arbitrary local files, configurations, and source code via a single HTTP POST request. This access enables the theft of credentials and secrets, which security experts warn could lead to lateral movement and supply chain compromise.

While GitLab patched 18 vulnerabilities in total, including a critical deserialization flaw, only CVE-2026-85706 is confirmed to be exploited in the wild. Security firm watchTowr reported observing active probes and warned that indiscriminate exploitation is likely imminent. GitLab confirmed that GitLab.com is already running the patched version and that Dedicated customers do not need to take action.


Reported across 5 outlets
Actors
GitLab Inc.Cybersecurity and Infrastructure Security Agency

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play