CISA adds GitLab path traversal to KEV list
CISA added CVE-2026-85706, a GitLab CE/EE path traversal flaw under active exploitation, to its Known Exploited Vulnerabilities catalog.
CISA has added one vulnerability, CVE-2026-85706, affecting GitLab Community Edition and Enterprise Edition, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. The flaw is a path traversal vulnerability, a class of bug frequently used by attackers to read or access files outside intended directories, potentially exposing sensitive data or enabling further compromise on affected GitLab instances.
Under Binding Operational Directive (BOD 26-04), Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that could grant an attacker full control post-exploitation, and to check for prior compromise before patching. While the directive is mandatory only for FCEB agencies, CISA recommends all organizations running GitLab CE/EE identify affected instances, apply vendor patches promptly, and review logs for indicators of exploitation predating remediation. No specific IOCs, threat actor attribution, or exploitation details were provided in this alert; organizations should consult GitLab's advisory for patch versions and further technical detail.
Defenders should treat this as a routine but time-sensitive patch-management action: confirm GitLab version exposure, prioritize internet-facing instances, and apply available fixes without delay given confirmed active exploitation.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free