โ Back to Feed
CISA: Hackers now exploit max severity GitLab flaw in attacks
CVE-2026-85706CVE-2021-22175CVE-2021-39935
September 14, 2026 ยท BleepingComputer ยท Severity: HIGH
CISA has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of the GitLab maximum-severity file-read flaw in ongoing attacks. The vulnerability allows unauthenticated attackers to read arbitrary files including source code and credentials from GitLab servers. ๐ **Analyst Note:** This is one of the fastest KEV additions we have observed โ a CVSS 10.0 added within days of patch release signals exceptionally aggressive exploitation, likely by nation-state actors or high-volume ransomware operations.
Key Takeaways
- CISA has confirmed that attackers are actively exploiting CVE-2026-85706, the maximum severity GitLab file-read vulnerability, in real-world attacks targeting unpatched GitLab servers across multiple sectors.
- The GitLab flaw combined with older CVEs (CVE-2021-22175, CVE-2021-39935) being leveraged in the same attack chain suggests attackers are chaining historic vulnerabilities for maximum impact.
- Organizations running GitLab must immediately apply emergency patches for CVE-2026-85706 as KEV inclusion means federal agencies face mandatory patching deadlines and exploit activity will escalate rapidly.