Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities

GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities

Posted on September 11, 2026 By CWS

GitLab has issued crucial security updates for its Community and Enterprise Editions, addressing multiple vulnerabilities, including two classified as critical. These flaws could potentially enable arbitrary file reads and credential theft, posing significant risks to users.

Critical Vulnerabilities and Their Impact

The company identified a high-severity flaw in its Enterprise Edition that might allow authenticated attackers to execute remote code by importing a malicious project export. The necessary patches have been released in versions 19.3.2, 19.2.6, and 19.1.8 as of September 10, 2026. Users of self-managed GitLab systems are strongly advised to apply these updates immediately, while GitLab.com has already implemented the patched versions.

Details of the Major Security Flaws

The most severe issue, tracked as CVE-2026-85706, involves a path traversal vulnerability within the repository commits API. This flaw affects both GitLab CE and EE, earning a maximum CVSS score of 10.0. Under specific conditions, it could allow an unauthenticated attacker to read arbitrary files from the server. This vulnerability results from inadequate path confinement and missing authentication checks.

Depending on the server setup, the exposed data could include application settings, secrets, tokens, SSH keys, or database credentials. The affected versions include GitLab CE and EE from 18.7 to before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The issue was reported by security researcher s3ntago through GitLab’s HackerOne bug bounty program.

Additional Security Concerns and Recommendations

Another critical flaw, identified as CVE-2026-87719, involves insecure deserialization in the GraphQL subscription serializer for GitLab EE. With a CVSS score of 9.9, this flaw requires authenticated user access to Duo Chat and could lead to credential and configuration theft. This vulnerability affects GitLab EE versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

Furthermore, GitLab addressed a buffer overflow vulnerability, CVE-2026-88765, in its Unicode conversion wrapper with a CVSS score of 8.5. This could allow an authenticated attacker to execute code remotely during Advanced Search indexing by importing a specially crafted Git project export.

The update also resolves high-severity issues related to protected CI/CD variables, Markdown rendering, and GraphQL resource handling. These vulnerabilities could enable unauthorized access to protected variables, unintended state changes, or denial-of-service conditions.

Importance of Timely Updates

GitLab urges administrators to upgrade to versions 19.3.2, 19.2.6, or 19.1.8 depending on their branch. The update includes database migrations, which will cause downtime for single-node deployments until completed. Multi-node deployments can utilize GitLab’s zero-downtime upgrade process if configured properly. Prompt updates are essential to protect sensitive data and maintain system security.

Cyber Security News Tags:arbitrary file read, credential theft, CVE-2026-85706, CVE-2026-87719, Cybersecurity, GitLab, remote code execution, security update, software patch, update urgency, Vulnerabilities

Post navigation

Previous Post: Surfshark Security Breach: No User Data Compromised

Related Posts

Critical Bing Images Flaws Patched Amid Security Concerns Critical Bing Images Flaws Patched Amid Security Concerns Cyber Security News
Telegram CEO Faces Terrorism Charges from Russia Telegram CEO Faces Terrorism Charges from Russia Cyber Security News
Threat Actors Using Multilingual ZIP File to Attack Financial and Goverment Organizations Threat Actors Using Multilingual ZIP File to Attack Financial and Goverment Organizations Cyber Security News
North Korean Hackers Infiltrated 136 U.S. Companies to Generate .2 Million in Revenue North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue Cyber Security News
Fake Notepad++ Mac Site Poses Cybersecurity Threat Fake Notepad++ Mac Site Poses Cybersecurity Threat Cyber Security News
OpenSSL Vulnerability ‘HollowByte’ Poses Severe Threat OpenSSL Vulnerability ‘HollowByte’ Poses Severe Threat Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark