Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitLab Patch Targeted by Attackers Within 24 Hours

GitLab Patch Targeted by Attackers Within 24 Hours

Posted on September 11, 2026 By CWS

Security experts have reported that a newly identified vulnerability in GitLab is being exploited by cybercriminals just one day after its public disclosure. The issue, known as CVE-2026-85706, is a critical path traversal flaw that poses significant risks, according to the attack surface management company, WatchTowr.

Details of the Vulnerability

The vulnerability, given a maximum severity score of 10 out of 10, permits unauthorized users to access and read files from the GitLab server. It affects all versions of the Community Edition (CE) and Enterprise Edition (EE) from 18.7 prior to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

WatchTowr has observed active attempts to exploit this vulnerability in the wild. These attempts were detected merely a day after GitLab released patches intended to mitigate this security flaw.

Exploitation and Defensive Measures

WatchTowr has noted that attackers are already probing for this path traversal vulnerability. The company advises defenders to scrutinize log files for HTTP POST requests directed at ‘/api/v4/projects/{id}/repository/commits/’ URIs that include ‘file.path’ parameters, which may indicate exploitation attempts.

To safeguard against this threat, it is imperative for those managing self-hosted GitLab instances to apply the latest patches immediately. These updates not only address the CVE-2026-85706 but also fix 17 other vulnerabilities, including another critical issue.

Additional Security Concerns

Among the other vulnerabilities addressed in the recent patch is CVE-2026-87719, a critical insecure deserialization flaw in the GraphQL subscription serializer. This flaw could potentially expose advanced search instance configurations and sensitive credentials to attackers.

Furthermore, the updates resolve six high-severity security issues that could lead to remote code execution, unauthorized access to CI/CD variables, cross-site scripting (XSS) attacks, and denial-of-service conditions.

Conclusion and Recommendations

The swift exploitation of GitLab’s vulnerability highlights the urgent need for timely patch implementations to protect against potential cyber threats. Organizations using affected GitLab versions should prioritize upgrading their systems immediately to prevent exploitation and secure their data.

Security Week News Tags:CVE-2026-85706, Cybersecurity, GitLab, path traversal, remote code execution, security patch, Software Security, Threat Actors, Vulnerability, WatchTowr

Post navigation

Previous Post: Russian Hackers Exploit AI to Revamp Undetected Malware
Next Post: KATARU IoT Malware: Linux Exploits and DDoS Tactics

Related Posts

CrowdStrike Plans Layoffs to Pursue B ARR Target CrowdStrike Plans Layoffs to Pursue $10B ARR Target Security Week News
Israel Leverages Iran’s Surveillance for Strategic Advantage Israel Leverages Iran’s Surveillance for Strategic Advantage Security Week News
Microsoft Awards  Million in Bug Bounties Microsoft Awards $20 Million in Bug Bounties Security Week News
Pixnapping Attack Steals Data From Google, Samsung Android Phones Pixnapping Attack Steals Data From Google, Samsung Android Phones Security Week News
OpenAI Among Victims in Axios Supply Chain Breach OpenAI Among Victims in Axios Supply Chain Breach Security Week News
SymJack Attack Exploits AI Coding Tools in Supply Chains SymJack Attack Exploits AI Coding Tools in Supply Chains Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing
  • Critical GitLab Vulnerability Under Active Exploitation
  • KATARU IoT Malware: Linux Exploits and DDoS Tactics
  • GitLab Patch Targeted by Attackers Within 24 Hours

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing
  • Critical GitLab Vulnerability Under Active Exploitation
  • KATARU IoT Malware: Linux Exploits and DDoS Tactics
  • GitLab Patch Targeted by Attackers Within 24 Hours

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark