โ† Back to Feed

CISA: Hackers now exploit max severity GitLab flaw in attacks

CVE-2026-85706CVE-2021-22175CVE-2021-39935

September 14, 2026 ยท BleepingComputer ยท Severity: HIGH

CISA has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of the GitLab maximum-severity file-read flaw in ongoing attacks. The vulnerability allows unauthenticated attackers to read arbitrary files including source code and credentials from GitLab servers. ๐Ÿ“Œ **Analyst Note:** This is one of the fastest KEV additions we have observed โ€” a CVSS 10.0 added within days of patch release signals exceptionally aggressive exploitation, likely by nation-state actors or high-volume ransomware operations.

Key Takeaways

  • CISA has confirmed that attackers are actively exploiting CVE-2026-85706, the maximum severity GitLab file-read vulnerability, in real-world attacks targeting unpatched GitLab servers across multiple sectors.
  • The GitLab flaw combined with older CVEs (CVE-2021-22175, CVE-2021-39935) being leveraged in the same attack chain suggests attackers are chaining historic vulnerabilities for maximum impact.
  • Organizations running GitLab must immediately apply emergency patches for CVE-2026-85706 as KEV inclusion means federal agencies face mandatory patching deadlines and exploit activity will escalate rapidly.
โ˜• Buy a Coffee