HomeIntelligenceBrief
VULNERABILITY BRIEF 🟠 High Advisory

CISA Adds Exploited GitLab Path Traversal (CVE‑2026‑85706) to KEV Catalog

CISA listed CVE‑2026‑85706, a path‑traversal vulnerability in GitLab CE/EE, in its Known Exploited Vulnerabilities catalog after confirming active attacks. Organizations must prioritize remediation to meet risk‑based governance and maintain audit‑ready evidence.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

CISA Adds Exploited GitLab Path Traversal (CVE‑2026‑85706) to KEV Catalog

What It Is — CISA announced that CVE‑2026‑85706, a path‑traversal flaw in GitLab Community and Enterprise Editions, is now listed in the Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation.

Exploitability — Evidence of real‑world attacks; the vulnerability grants an attacker file‑system access that can lead to full control of the affected host. No public CVSS score yet, but the exploitation evidence places it in the high‑risk tier.

Affected Products — GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) – all supported versions prior to the vendor‑released fix.

Why It Matters for Trust & Control Assurance

  • Continuous vulnerability monitoring is a core control; a KEV listing signals an immediate need for evidence of remediation.
  • Demonstrating rapid patching against a CISA‑approved list satisfies risk‑based governance expectations for federal and private enterprises alike.
  • Maintaining auditable records of remediation actions strengthens the control objective of “Vulnerability Management” across multiple frameworks (e.g., NIST CSF, ISO 27001).

Recommended Actions

  1. Inventory all publicly exposed GitLab instances and verify version details.
  2. Apply the vendor‑released patch or mitigation guidance without delay.
  3. Record the remediation step in your vulnerability‑management system and retain proof for audit reviews.
  4. Incorporate the KEV catalog into your risk‑based patch‑prioritization process (BOD 26‑04).

Source: CISA Advisory – 2026‑09‑11

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →