As cited
Copy frozen at (site build).
vulnerabilities
GitLab security advisory (AV26-917)
GitLab released critical patches (versions 19.3.2, 19.2.6, and 19.1.8) to address vulnerabilities affecting prior versions. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities database on September 11, 2026, indicating active exploitation in the wild.
Why it matters: GitLab users running versions before 19.1.8, 19.2.6, or 19.3.2 face immediate risk from CVE-2026-85706 and should prioritize patching today, as the vulnerability is listed in CISA's KEV catalog signaling active threat activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
GitLab security advisory (AV26-917)
GitLab addressed vulnerabilities affecting versions prior to 19.1.8, 19.2.6, and 19.3.2. CVE-2026-85706 was added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities database on September 11, 2026, indicating active exploitation. The Cyber Centre recommends users and administrators apply available patches immediately.
Why it matters: GitLab administrators and users running affected versions face active exploitation risk and must prioritize patching to versions 19.1.8, 19.2.6, or 19.3.2 today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
GitLab security advisory (AV26-917)
GitLab addressed vulnerabilities in versions prior to 19.1.8, 19.2.6, and 19.3.2 with critical patch releases. CVE-2026-85706 (CVSS 10.0) was added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) database on September 11, 2026, indicating active exploitation.
Why it matters: GitLab administrators managing affected instances must update immediately, as CVE-2026-85706 is actively exploited and represents a critical risk to their deployments.
- Source published
- First seen by Cybersecurity Tracker