PROBED

GitLab CVE-2026-85706 is CVSS 10. WatchTowr saw probes one day after the patch.

Unauthenticated arbitrary file read via the repository commits API. Self-managed CE/EE must move to 19.3.2 / 19.2.6 / 19.1.8. GitLab.com is already patched; Dedicated needs no action. Victim count: Undisclosed.

Sep 11, 2026 · 3 min read

GitLab’s September 10 critical patch release fixed CVE-2026-85706 — a path traversal in the repository commits API rated CVSS 10.0. Under certain conditions an unauthenticated caller can read arbitrary files from the GitLab server. Impacted: CE/EE from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Fixed builds: 19.3.2, 19.2.6, 19.1.8.

SecurityWeek (Sep 11, 12:11 PM ET) reports WatchTowr Intel already observing in-the-wild probes for the flaw one day after disclosure — HTTP POSTs to /api/v4/projects/{id}/repository/commits/ with file.path parameters. WatchTowr expects mass exploitation to follow. That is probe/exploitation-attempt telemetry, not a published breach tally; compromise counts: Undisclosed.

Same release also ships CVE-2026-87719 (CVSS 9.9) — insecure GraphQL subscription deserialization on EE that can expose Advanced Search configs and sensitive credentials to an authenticated Duo Chat user — plus six Highs. Underwrite sheet: primary is GitLab’s patch notes; secondary is SecurityWeek / WatchTowr on probes. Patch self-managed now.

Sources