Find notable cyber news and cases, enriched with sources, timelines, and signals.

GitLab CE/EE security update for CVE-2026-85706

Security Patch Release
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and secrets. The update covers GitLab Community Edition (CE) and Enterprise Edition (EE), including 19.3.2, 19.2.6, and 19.1. The patch release matters because vulnerable servers can leak sensitive information through unauthenticated requests.

Related Happenings

GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)

Security Patch Release
H score45 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

About this happening: GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...

GitLab self-managed installations immediate upgrade advisory

Advisory/Mitigation
H score45 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

About this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...

HPE ArubaOS-CX security bulletin (CVE-2026-73749)

Security Patch Release
H score31 First: 03.09.2026 21:28 Last: 03.09.2026 21:28 Sources 1

About this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...

GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650

Security Patch Release
H score31 First: 18.08.2026 00:03 Last: 18.08.2026 00:03 Sources 1

About this happening: GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...

Latest development: 21.08.2026 10:04

watchTowr observed in-the-wild exploitation of GitLab CVE-2026-19478 against its honeypot network and said it could reproduce the flaw within minutes of disclosure. GitLab said the issue could be exploited via a GraphQL directive, and defenders were told to hunt web logs for requests containing '@gl_introduced' and to restrict unauthenticated access to "/api/graphql" if patching is not immediately possible.

Gitea security patch release for CVE-2026-59774

Security Patch Release
H score65 First: 05.08.2026 14:04 Last: 05.08.2026 14:04 Sources 1

About this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...

Timeline

  1. 14.09.2026 10:06 2 articles · 2h ago

    GitLab releases CE/EE fixes for CVE-2026-85706

    Mitigation Patch Update

    GitLab released fixes for CVE-2026-85706 in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1, and urged administrators to patch immediately to close a repository commits API flaw that can expose credentials, secrets, and other sensitive data.

    Show sources
  2. 14.09.2026 10:06 1 articles · 2h ago

    watchTowr observes in-the-wild probes for CVE-2026-85706

    Detection Ioc Update

    watchTowr observed in-the-wild probes for CVE-2026-85706 against Internet-facing GitLab servers that had not been patched, indicating active scanning for a path traversal issue that can let attackers read arbitrary files through the repository commits API.

    Show sources
  3. 14.09.2026 10:06 1 articles · 2h ago

    CISA adds CVE-2026-85706 to its actively exploited catalog

    Legal Policy Action Update

    CISA added CVE-2026-85706 to its catalog of actively exploited vulnerabilities and gave federal agencies three days under Binding Operational Directive (BOD) 26-04 to secure affected systems, while urging all organizations to remediate the GitLab flaw quickly.

    Show sources