Critical unauthenticated vulnerabilities in GitLab development software are drawing active exploitation by malicious actors within 24 hours of public disclosure, according to warnings issued by the Cybersecurity and Infrastructure Security Agency (CISA), watchTowr, and the Hong Kong Computer Emergency Response Team.
CVE-2026-85706 Flaw Details and Threat Actor Activity
Tracked as CVE-2026-85706, the maximum severity vulnerability carries a CVSS score of 10. According to CISA and security analysts, the flaw stems from a lack of authentication requirements paired with missing restrictions on file placement. This combination allows malicious actors to execute a full file read on affected GitLab servers without authorization.
GitLab released a patch for CVE-2026-85706 on September 10, according to public disclosures. However, threat actors mobilized rapidly. The cybersecurity firm watchTowr reported observing in-the-wild probes targeting servers running vulnerable versions of the development platform. According to watchTowr intelligence analysts, hackers are leveraging the flaw to read local configuration files, harvest credentials, and extract sensitive system secrets.
The Hong Kong Computer Emergency Response Team issued an advisory warning that the vulnerability was being actively exploited in the wild. In response to the rapid weaponization of the bug, CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. The federal agency established a strict remediation deadline, directing federal civilian executive branch agencies to mitigate the associated risks by Monday.
Additional GitLab Security Updates
Alongside the critical unauthenticated file read vulnerability, GitLab addressed a secondary security weakness in its enterprise edition. According to GitLab’s security updates, the platform patched CVE-2026-87719 on a Thursday release. This second flaw could have allowed attackers to obtain sensitive information from servers running the enterprise software edition.
These recent incidents form part of a broader pattern of security disclosures affecting GitLab infrastructure. GitLab previously disclosed CVE-2025-0376 in early 2025, followed by CVE-2026-1092, CVE-2025-12664, and CVE-2026-5173 in April of that year. More recently, the company disclosed critical flaw CVE-2026-19478 in August, which also triggered rapid exploitation by hackers within days of release, according to historical tracking data.
Mitigation and Response Requirements
Security teams are urged to apply official patches supplied by GitLab to close the authentication gaps exploited by CVE-2026-85706.