“Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” WatchTowr Labs warned in a LinkedIn post — a sober note that arrived as GitLab pushed emergency fixes for two severe flaws in its platform.
What GitLab patched on Thursday
GitLab released emergency patches Thursday for two high-severity vulnerabilities in its software development platform and urged operators of self‑managed installations to upgrade as soon as possible. The company said its own hosted service already runs the corrected code, and that customers of its single‑tenant Dedicated offering are not impacted.
The more serious defect is tracked as CVE-2026-85706. GitLab assigned it a CVSS score of 10.0. According to the company, the flaw sits in the interface that handles repository commits; under certain conditions an attacker could read any file on the server because the code failed to confine file paths properly and did not enforce authentication. An attacker does not need an account or credentials to exploit the bug. GitLab said the vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches.
The second issue, CVE-2026-87719, affects only GitLab’s Enterprise Edition and carries a CVSS score of 9.9. The company said a logged‑in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature and return the settings and passwords being held. That flaw affects releases from 18.3 onward.
How probes and detection look in the wild
Security firm WatchTowr Labs reported Friday that it was already seeing probes for the path‑traversal flaw. The firm said an attacker can trigger the CVE-2026-85706 bug in a single HTTP request and that organizations running self‑hosted GitLab servers reachable from the open internet face the greatest risk.
WatchTowr Labs pointed defenders toward log indicators: look for POST requests to addresses under /api/v4/projects/{{id}}/repository/commits/ that carry a file.path parameter. The firm also warned that, drawing on earlier GitLab flaws, broad untargeted attacks tend to follow soon after a patch appears.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWho is affected — and who is not
According to GitLab’s advisory and the firm’s public statements, the greatest exposure lies with self‑managed instances that are reachable from the internet and have not yet applied the emergency patches. The CVE-2026-85706 vulnerability affected Community Edition and Enterprise Edition releases from 18.7 through 19.3 lines prior to the update, while CVE-2026-87719 impacted Enterprise Edition releases from 18.3 onward.
GitLab reported that its hosted service had already been updated with the fixes, and that single‑tenant Dedicated customers are not impacted by these specific flaws.
How CISA and defenders are positioned
As of Friday afternoon, the Cybersecurity and Infrastructure Security Agency (CISA) had not added the two vulnerabilities to its Known Exploited Vulnerabilities (KEV) list. Despite that, GitLab’s public urging to upgrade immediately and WatchTowr Labs’ observation of internet scanning make timely patching and log review immediate priorities for defenders with exposed instances.
What this means for security teams, enterprise IT leaders, and the public
- Security teams and technologists: Expect rapid, broad probing after the public patch. WatchTowr Labs’ indicators — POSTs to /api/v4/projects/{{id}}/repository/commits/ with a file.path parameter — provide a concrete starting point for log searches and IDS signatures.
- Enterprise IT and procurement leaders: The affected release ranges for both flaws (Community and Enterprise Edition lines back to 18.7 and 18.3 respectively) mean many older self‑managed installations could be exposed; GitLab’s advice to upgrade as soon as possible is directly relevant to risk posture and patch‑management cycles.
- The general public and downstream users: While GitLab’s hosted service was reported as already fixed and Dedicated customers were not impacted, organizations that host their own GitLab instances on internet‑facing infrastructure should treat the bulletin as an operational priority to reduce the risk of data disclosure.
GitLab’s emergency patches close two sharply rated flaws: a path‑traversal, unauthenticated read bug given a 10.0 CVSS score (CVE-2026-85706), and a nearly as severe Enterprise Edition issue (CVE-2026-87719) scored at 9.9. WatchTowr Labs’ early detection of probes and its blunt reminder that “indiscriminate exploitation is likely not far away” turn what might have been a routine patch cycle into an urgent security event for self‑hosted instances. Whether CISA will place the flaws on its KEV list and how quickly untargeted attackers scale probing remain the immediate, concrete questions left on the table.
Source: CyberScoop — GitLab’s critical flaw is already drawing internet-wide probes




