Cybersecurity Dive·2 min read

Malicious actors already using critical GitLab flaw, CISA and others warn

E
Eric Geller
Malicious actors already using critical GitLab flaw, CISA and others warn
Dive DeeperCreate a free account to unlock

The vulnerability could let unauthenticated users access sensitive files from software-development environments.

Hackers have begun exploiting a serious vulnerability in a popular software development tool, the Cybersecurity and Infrastructure Security Agency is warning.

CISA on Friday listed the vulnerability in GitLab’s development platform in its Known Exploited Vulnerabilities catalog, giving federal agencies until Monday to mitigate the risks associated with the flaw.

The vulnerability, tracked as CVE-2026-85706 , involves a lack of authentication requirements and a lack of restrictions on where users can place files. Malicious actors could exploit the flaw to access files on GitLab servers without authorization. GitLab released a patch for the flaw on Sept. 10.

In issuing a CVE for the vulnerability, GitLab assigned it the maximum score of 10, indicating a critical flaw that organizations should patch as soon as possible. But for some organizations, it is already too late.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in