Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706

Public Sector Action
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the GitLab flaw into an urgent federal remediation priority and increases pressure on agencies running exposed servers. CISA also urged all organizations to prioritize remediation of KEV Catalog vulnerabilities.

Related Happenings

GitLab CE/EE repository commits API path traversal (CVE-2026-85706)

Vulnerability
H score43 First: 14.09.2026 10:06 Last: 14.09.2026 10:06 Sources 1

How related: The security flaw (tracked as CVE-2026-85706) stems from missing authentication enforcement and improper path confinement in the repository commits API, and unauthenticated attackers can exploit it to read credentials, secrets, and other sensitive information from vulnerable servers.

About this happening: CISA added CVE-2026-85706 to its actively exploited catalog after GitLab CE/EE servers were probed and attacked, increasing the risk of credential and secret disclosure*...

GitLab self-managed installations immediate upgrade advisory

Advisory/Mitigation
H score45 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

About this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...

GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)

Security Patch Release
H score45 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

About this happening: GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...

GitLab repository commits API path traversal vulnerability (CVE-2023-2825)

Vulnerability
H score33 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

About this happening: GitLab has a maximum-severity path traversal vulnerability, CVE-2023-2825, that can let unauthenticated attackers read arbitrary files from vulnerable servers...

GitLab notebook diff authenticated RCE flaw

Vulnerability
H score37 First: 25.07.2026 11:34 Last: 25.07.2026 11:34 Sources 1

About this happening: A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE...

Timeline

  1. 14.09.2026 10:06 2 articles · 2h ago

    CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706

    Initial Disclosure

    CISA placed CVE-2026-85706 in its actively exploited catalog and set a three-day remediation window for federal agencies under BOD 26-04.

    Show sources