GitLab security advisory (AV26-917)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-917 Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 | GitLab Docs GitLab release notes | GitLab Docs CISA KEV: CVE-2026-85706
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-85706Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 65% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85706 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editionsncsc-nl
- criticalexploitedCVE-2026-85706: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8,…nvd
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- highexploited[NEU] [hoch] GitLab: Mehrere Schwachstellencert-bund
- criticalexploitedCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerabilitycisa-kev
- unknownexploitedMultiples vulnérabilités dans GitLab (11 septembre 2026)cert-fr-avis
- criticalexploitedGitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8gitlab
More from Canadian Centre for Cyber Security
- unknownJFrog security advisory (AV26-867) – Update 22026-09-11
- unknownn8n security advisory (AV26-916)2026-09-11
- unknownConnectWise security advisory (AV26-903) – Update 12026-09-11
- criticalProgress security advisory (AV26-915)2026-09-11
- unknown[Control Systems] National Instruments security advisory (AV26-914)2026-09-11