[NEU] [hoch] GitLab: Mehrere Schwachstellen
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Ein Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, sensible Informationen oder Anmeldedaten offenzulegen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen oder Denial-of-Service-Zustände zu verursachen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3315
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editionsncsc-nl
- criticalCVE-2026-87719: GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19…nvd
- criticalexploitedCVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8,…nvd
- criticalexploitedGitLab security advisory (AV26-917)cccs
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerabilitycisa-kev
- unknownexploitedMultiples vulnérabilités dans GitLab (11 septembre 2026)cert-fr-avis
- criticalexploitedGitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8gitlab
Recent advisories for GitLab
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownexploitedNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editionsncsc-nl · 2026-09-12
- criticalCVE-2026-87719: GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19…nvd · 2026-09-12
- criticalexploitedCVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8,…nvd · 2026-09-12
- criticalexploitedGitLab security advisory (AV26-917)cccs · 2026-09-11
- unknownexploitedMultiples vulnérabilités dans GitLab (11 septembre 2026)cert-fr-avis · 2026-09-11
- criticalexploitedCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerabilitycisa-kev · 2026-09-11
More from CERT-Bund (BSI) Security Advisories
- high[UPDATE] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Service2026-09-11
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-11
- high[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen2026-09-11