Wire · technology
GitLab's Critical Patch Closes a Path Traversal Flaw Attackers Are Already Probing
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 14 September 2026 · Fusion42 review
GitLab released critical patches fixing a maximum severity vulnerability that allows unauthenticated attackers to read arbitrary files on self-managed servers, amid active exploitation attempts; a second critical flaw enables authenticated users to steal sensitive credentials. The key risk lies in the slow patch cycles for self-managed instances that lag behind rapid attacker probing.
This Wire brief sits within Fusion42's coverage of Developer Tools, Cybersecurity and Enterprise Software, and 2 sources have reported it between 12 Sep 2026 and 14 Sep 2026.
◆ ◆ The Wire takeaway
Your self-managed GitLab could be an open door for attackers fast exploiting new bugs. Patch immediately to stop attackers who are probing right now and avoid irreversible damage to your platform security.
◆ Coverage
2 sources · first reported 12 Sep 2026 · latest 14 Sep 2026
◆ Related on Wire
◆ Topics