← Back

Wire · regulatory

Max severity GitLab path traversal flaw under active reconnaissance

Published

12 September 2026

Topic

regulatory

Sectors

CybersecurityEnterprise Software

Source

Read at scworld.com

Verified

Fusion42 · 12 September 2026 · Fusion42 review

GitLab patched a critical path traversal vulnerability (CVE-2026-85706) in self-managed instances that allows unauthenticated access to arbitrary files, including sensitive credentials, actively probed in the wild with a maximum CVSS score of 10.0.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software, and 2 sources have reported it between 12 Sep 2026 and 14 Sep 2026.

◆ The Wire takeaway

You must act now to patch self-managed GitLab instances or risk severe breaches from active attacks exploiting this critical flaw. Your customers’ source code and secrets depend on your swift upgrade.

Coverage

2 sources · first reported 12 Sep 2026 · latest 14 Sep 2026

Related on Wire

Topics

CybersecurityEnterprise Softwaregitlabsecurityvulnerabilitypath-traversalcritical-patchactive-exploitation