The vulnerability could let unauthenticated users access sensitive files from software-development environments.
Hackers have begun exploiting a serious vulnerability in a popular software development tool, the Cybersecurity and Infrastructure Security Agency is warning.
CISA on Fridaylisted the vulnerabilityin GitLab’s development platform in its Known Exploited Vulnerabilities catalog, giving federal agencies until Monday to mitigate the risks associated with the flaw.
The vulnerability, tracked asCVE-2026-85706, involves a lack of authentication requirements and a lack of restrictions on where users can place files. Malicious actors could exploit the flaw to access files on GitLab servers without authorization. GitLabreleased a patch for the flawon Sept. 10.
In issuing a CVE for the vulnerability, GitLab assigned it the maximum score of 10, indicating a critical flaw that organizations should patch as soon as possible. But for some organizations, it is already too late.
The cybersecurity firm watchTowrsaid on Fridaythat its intelligence analysts were “already observing in-the-wild probes” for servers running vulnerable versions of GitLab. The firm warned that hackers could use the flaw to “read local files and configs to obtain credentials, secrets, and sensitive information.”
“Based on recent GitLab vulnerabilities,” watchTowr added, “we know the time until indiscriminate exploitation is likely not far away.”
Hong Kong’s computer emergency response teamreleased an advisoryabout the flaw on Monday, warning that it was “being exploited in the wild.”
In its security update on Thursday, GitLab also patched a second vulnerability,CVE-2026-87719, which could have allowed attackers to obtain sensitive information from servers running GitLab’s enterprise edition.
The new vulnerabilities are the latest major security weaknesses in GitLab’s products. The company disclosedCVE-2025-0376in early 2025, as well as three more —CVE-2026-1092,CVE-2025-12664andCVE-2026-5173— in April. GitLab disclosed another critical flaw,CVE-2026-19478, in August, prompting hackers to begin exploiting it within days.
Filed Under:Vulnerability,Cyberattacks,Threats
