Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical GitLab Vulnerability Under Active Exploitation

Critical GitLab Vulnerability Under Active Exploitation

Posted on September 11, 2026 By CWS

GitLab has issued updates to fix several security vulnerabilities, including a critical flaw that has been targeted by attackers shortly after its disclosure. The flaw, identified as CVE-2026-85706, has a CVSS score of 10.0, indicating its potential severity. This path traversal vulnerability in the repository commits API could permit unauthorized users to access arbitrary files on the GitLab server under specific conditions.

Details of the Vulnerability

The issue arises from improper path restriction and the lack of authentication enforcement in the API. It affects various versions of GitLab Community Edition (CE) and Enterprise Edition (EE). Specifically, all versions from 18.7 up to but not including 19.1.8, 19.2 up to 19.2.6, and 19.3 up to 19.3.2 are vulnerable.

According to watchTowr, a company specializing in exposure management, active exploitation of this vulnerability started at 06:00 UTC on September 11, 2026. Attackers could use this flaw to read log files and configuration files, potentially gaining access to credentials and sensitive data.

Threat Landscape and Implications

Jake Knott, head of threat intelligence at watchTowr, highlighted that this is the second severe GitLab vulnerability in recent weeks. The previous one involved a GraphQL code injection (CVE-2026-19478) that was also rapidly exploited. The current vulnerability allows attackers to access source code, CI/CD secrets, and inject code into build pipelines, posing significant risks.

The allure of exploiting GitLab lies in the unauthorized access it provides, which can lead to further malicious activities in downstream systems. As seen throughout the year, attackers have increasingly targeted such vulnerabilities to gain deeper access to IT infrastructures.

Mitigation and Recommendations

In response, GitLab has also addressed another critical issue in versions 19.3.2, 19.2.6, and 19.1.8. This insecure deserialization flaw (CVE-2026-87719, CVSS score: 9.9) could expose sensitive information if exploited by an authenticated user.

Organizations operating self-managed GitLab instances should urgently apply these patches to prevent unauthorized access. If immediate patching is not feasible, limiting public access is recommended. Knott advises monitoring log files for suspicious HTTP POST requests to the repository commits API to detect potential exploitation attempts.

Given the rapid transition of these vulnerabilities to widespread exploitation, timely action is crucial to safeguard against potential security breaches. Organizations are urged to prioritize these patches to protect their data and systems effectively.

The Hacker News Tags:CVSS 10, Cybersecurity, data breach, GitLab, IT security, Patches, security vulnerability, Software Security, threat intelligence, web security

Post navigation

Previous Post: KATARU IoT Malware: Linux Exploits and DDoS Tactics
Next Post: Phishing Study Reveals New Insights on Security Testing

Related Posts

CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited The Hacker News
Critical LiteLLM Vulnerability Leads to Exploits Critical LiteLLM Vulnerability Leads to Exploits The Hacker News
Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow The Hacker News
Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions The Hacker News
CISO’s Expert Guide To AI Supply Chain Attacks CISO’s Expert Guide To AI Supply Chain Attacks The Hacker News
Critical Cisco Nexus Flaw Allows Remote Code Execution Critical Cisco Nexus Flaw Allows Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark