GitLab CVE-2026-85706: CVSS 10.0 Flaw Under Attack
GitLab disclosed a critical flaw (CVE-2026-85706) in its repository commits API, scoring a perfect CVSS 10.0. The bug allows unauthenticated attackers to read arbitrary files. GitLab released patches, but active exploitation was observed within 24 hours. CISA added the flaw to its Known Exploited Vulnerabilities catalog, urging immediate action.
How this was made
The 30-second read
Why it matters
The rapid move from disclosure to active exploitation underscores urgency for customers to upgrade.
Market read
Security breach risk may depress GITLAB stock and boost security‑vendor equities.
What to watch
Potential surge in demand for third‑party security solutions and managed GitLab services.
Background
GitLab released patches on Sep 10; CISA added the vulnerability to its KEV catalog on Sep 11.
Market effects
Highlights broader software supply‑chain security concerns for DevOps tools.
US and European cloud‑service providers may see heightened scrutiny.
Sets precedent for rapid KEV listings affecting multiple tech firms.
Counterpoint
If GitLab.com SaaS remains fully patched, impact may be limited to self‑hosted users.
Key entities
- CompanyGitLab
Provider of DevOps platform, ticker GITLAB.
- AgencyCISA
U.S. Cybersecurity and Infrastructure Security Agency, added CVE to KEV list.





