NewsTradingSentimentCalendarCommunityBriefing
Tech

GitLab Patches Critical Flaw as Attackers Probe Exposed Servers

By Tech Desk · 2026-09-13 · 2 min read
A server rack with blinking status lights
Illustration: Tradingbird

GitLab has released emergency patches for a severe security flaw that allows unauthorized users to read sensitive data, with early signs indicating that malicious actors have already begun scanning for vulnerable systems.

GitLab advised all self-managed users to immediately update their servers to address a maximum-severity path traversal vulnerability identified as CVE-2026-85706. This flaw arises from improper path confinement and a lack of authentication checks within the repository commits API, creating a significant security gap in the platform.

The vulnerability permits unauthenticated attackers to read arbitrary data from vulnerable servers under specific conditions. This includes access to credentials, secrets, and other sensitive information. While GitLab has not yet confirmed widespread exploitation, security firm watchTowr reported that attackers are already probing Internet-exposed GitLab instances for this specific weakness.

Attackers are already scanning for the flaw

watchTowr noted that their intelligence is observing in-the-wild probes for CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request. The company warned that based on the history of GitLab vulnerabilities, the window before indiscriminate exploitation is likely to be short. Defenders are advised to hunt through log files for specific HTTP POST requests to identify potential exploitation attempts early.

In a separate incident, GitLab patched a second critical vulnerability tracked as CVE-2026-87719. This issue stems from an insecure deserialization weakness in the GraphQL subscription serializer. It affects GitLab Enterprise Edition and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.

Urgent updates required for all versions

GitLab fixed these security issues in versions 19.3.2, 19.2.6, and 19.1, urging users to upgrade immediately. The company stated that these versions contain important bug and security fixes. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take any action. However, self-managed installations are at risk if they remain on older versions.

This is not the first time GitLab has faced such severe issues. In May 2023, the platform addressed a similar maximum-severity path traversal flaw that exposed proprietary code and user credentials. More recently, in January, GitLab patched a high-severity two-factor authentication bypass. These repeated incidents highlight the persistent challenges in maintaining robust security for widely used development platforms.

A pattern of recurring security issues

Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency has flagged four GitLab vulnerabilities as exploited in attacks. Two of these were confirmed in February this year. The GitLab DevSecOps platform has more than 30 million registered users and is used by over 50% of Fortune 100 companies, including major organizations like Nvidia, Airbus, and Goldman Sachs.

As reported by BleepingComputer, the scale of GitLab's user base means that any significant vulnerability has a broad impact. The company's rapid response to patch these critical flaws is a necessary step to mitigate the risk of data breaches and unauthorized access for its vast community of developers and enterprises.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories
  • A server rack with blinking status lights
    Illustration: Tradingbird

    AWS Releases Benchmark to Test AI Agents on Live Cloud Tasks

    AWS has released a new open-source tool that grades AI agents on their ability to manage live cloud infrastructure, moving beyond static code tests to measure real-world operational safety and cost.

    2026-09-13
  • A vast industrial landscape featuring rows of large, white rectangular cooling towers and server buildings under a clear sky
    Illustration: Tradingbird

    Microsoft Aims to Triple Data Centre Capacity by 2032

    Microsoft is reportedly planning a massive expansion of its data centre infrastructure, targeting 38 gigawatts of capacity by 2032. This would more than triple its current footprint, driven by surging demand for AI workloads.

    2026-09-13
  • A vast, dimly lit server room with rows of tall, black metal cabinets stretching into the distance, illuminated by soft blue status lights.
    Illustration: Tradingbird

    Oracle's Cloud Backlog Near Matches Microsoft's

    Oracle reported a sharp rise in cloud infrastructure revenue and a contract backlog that now rivals Microsoft's, signaling a shift in the competitive landscape.

    2026-09-13