A critical vulnerability in GitLab, known as CVE-2026-85706, has been identified and is being actively exploited by threat actors, prompting urgent calls for users to apply necessary patches. This vulnerability, described as a path traversal flaw, allows unauthorized access to restricted directories, enabling attackers to read arbitrary files on the server. GitLab has addressed this issue, releasing fixes for affected versions on September 10. The flaw impacts GitLab CE/EE versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

Despite GitLab not acknowledging active exploitation, cybersecurity firm WatchTowr reported detecting real-world probes for this vulnerability on September 11. This discovery highlights the urgency for organizations with public-facing, self-hosted GitLab instances to implement patches immediately or revoke public access to mitigate potential threats. The United States Cybersecurity and Infrastructure Security Agency (CISA) has also recognized the threat, adding CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. CISA's guidance emphasizes the importance of addressing this vulnerability, particularly for civilian federal agencies, which must comply by September 15, as well as advising private sector organizations to follow suit.

The rapid pace at which hackers are exploiting vulnerabilities is partly attributed to advancements in AI, which aid in weaponizing and discovering new security gaps. A recent example involved the use of AI to identify and exploit a zero-day vulnerability, underscoring the evolving nature of cyber threats and the need for vigilant security practices.