Our takeCISA added CVE-2026-85706 to the KEV catalog; GitLab fixed it in 19.1.8, 19.2.6, and 19.3.2. Update self-hosted instances now.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update self-hosted GitLab instances to 19.1.8, 19.2.6 or 19.3.2 immediately. CISA added CVE-2026-85706 to the KEV catalog, confirming active exploitation.
What this means for you — Lean IT orgs:If you run your own GitLab server, update it to 19.1.8, 19.2.6 or 19.3.2 right away. CISA says attackers are already using this flaw.
What this means for you — MSP:Check every client self-hosted GitLab deployment and update to 19.1.8, 19.2.6 or 19.3.2. CISA added the CVE to KEV on 10 Sep, confirming in-the-wild exploitation.
What this means for you — Researcher:CISA added CVE-2026-85706 to KEV on 10 Sep; GitLab fixed it in 19.1.8, 19.2.6 and 19.3.2. Update self-hosted instances now.