THREAT OPS › Threat News › CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
<p></p><h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style="font-size: undefined;">On September 10, 2026, GitLab </span><a href="https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/"><span style="font-size: undefined;">published a critical patch release</span></a><span style="font-size: undefined;"> for GitLab Community Edition (CE) and Enterpr
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-85706cve
- CVE-2026-87719cve
- https://www.cve.org/CVERecord?id=CVE-2026-85706url
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:Nurl
- https://www.cve.org/CVERecord?id=CVE-2026-87719url
- https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:Hurl