GitLab CE/EE security update for CVE-2026-85706
Security Patch Release
Summary
Hide ▲
Show ▼
GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and secrets. The update covers GitLab Community Edition (CE) and Enterprise Edition (EE), including 19.3.2, 19.2.6, and 19.1. The patch release matters because vulnerable servers can leak sensitive information through unauthenticated requests.
Related Happenings
GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch Release
H score45
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
About this happening:
GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...
GitLab CE/EE security patch release (CVE-2023-2825, CVE-2026-87719)
Security Patch ReleaseAbout this happening: GitLab released fixes for CVE-2023-2825 and CVE-2026-87719 in GitLab Community Edition (CE) and Enterprise Edition (EE), requiring self-managed installations...
GitLab self-managed installations immediate upgrade advisory
Advisory/Mitigation
H score45
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
About this happening:
GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
GitLab self-managed installations immediate upgrade advisory
Advisory/MitigationAbout this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch Release
H score31
First: 03.09.2026 21:28
Last: 03.09.2026 21:28
Sources 1
About this happening:
HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch ReleaseAbout this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch Release
H score31
First: 18.08.2026 00:03
Last: 18.08.2026 00:03
Sources 1
About this happening:
GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...
GitLab CE/EE security update for CVE-2026-19478 and CVE-2026-19650
Security Patch ReleaseAbout this happening: GitLab released out-of-band security updates on August 17, 2026 for GitLab CE/EE to fix CVE-2026-19478, a critical GraphQL issue that could let an unauth...
Latest development: 21.08.2026 10:04
watchTowr observed in-the-wild exploitation of GitLab CVE-2026-19478 against its honeypot network and said it could reproduce the flaw within minutes of disclosure. GitLab said the issue could be exploited via a GraphQL directive, and defenders were told to hunt web logs for requests containing '@gl_introduced' and to restrict unauthenticated access to "/api/graphql" if patching is not immediately possible.
Gitea security patch release for CVE-2026-59774
Security Patch Release
H score65
First: 05.08.2026 14:04
Last: 05.08.2026 14:04
Sources 1
About this happening:
Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Gitea security patch release for CVE-2026-59774
Security Patch ReleaseAbout this happening: Gitea 1.27.1 is a security patch release that closes CVE-2026-59774 and CVE-2026-60004, reducing exposure for self-hosted Gitea deployments. The update fixes a C...
Timeline
-
14.09.2026 10:06 2 articles · 2h ago
GitLab releases CE/EE fixes for CVE-2026-85706
Mitigation Patch UpdateGitLab released fixes for CVE-2026-85706 in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1, and urged administrators to patch immediately to close a repository commits API flaw that can expose credentials, secrets, and other sensitive data.
Show sources
- CISA: Hackers now exploit max severity GitLab flaw in attacks — www.bleepingcomputer.com — 14.09.2026 10:06
- CISA: Hackers now exploit max severity GitLab flaw in attacks — www.bleepingcomputer.com — 14.09.2026 10:06
-
14.09.2026 10:06 1 articles · 2h ago
watchTowr observes in-the-wild probes for CVE-2026-85706
Detection Ioc UpdatewatchTowr observed in-the-wild probes for CVE-2026-85706 against Internet-facing GitLab servers that had not been patched, indicating active scanning for a path traversal issue that can let attackers read arbitrary files through the repository commits API.
Show sources
- CISA: Hackers now exploit max severity GitLab flaw in attacks — www.bleepingcomputer.com — 14.09.2026 10:06
-
14.09.2026 10:06 1 articles · 2h ago
CISA adds CVE-2026-85706 to its actively exploited catalog
Legal Policy Action UpdateCISA added CVE-2026-85706 to its catalog of actively exploited vulnerabilities and gave federal agencies three days under Binding Operational Directive (BOD) 26-04 to secure affected systems, while urging all organizations to remediate the GitLab flaw quickly.
Show sources
- CISA: Hackers now exploit max severity GitLab flaw in attacks — www.bleepingcomputer.com — 14.09.2026 10:06