CISA Adds Exploited GitLab Path Traversal (CVE‑2026‑85706) to KEV Catalog
What It Is — CISA announced that CVE‑2026‑85706, a path‑traversal flaw in GitLab Community and Enterprise Editions, is now listed in the Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation.
Exploitability — Evidence of real‑world attacks; the vulnerability grants an attacker file‑system access that can lead to full control of the affected host. No public CVSS score yet, but the exploitation evidence places it in the high‑risk tier.
Affected Products — GitLab Community Edition (CE) and GitLab Enterprise Edition (EE) – all supported versions prior to the vendor‑released fix.
Why It Matters for Trust & Control Assurance
- Continuous vulnerability monitoring is a core control; a KEV listing signals an immediate need for evidence of remediation.
- Demonstrating rapid patching against a CISA‑approved list satisfies risk‑based governance expectations for federal and private enterprises alike.
- Maintaining auditable records of remediation actions strengthens the control objective of “Vulnerability Management” across multiple frameworks (e.g., NIST CSF, ISO 27001).
Recommended Actions
- Inventory all publicly exposed GitLab instances and verify version details.
- Apply the vendor‑released patch or mitigation guidance without delay.
- Record the remediation step in your vulnerability‑management system and retain proof for audit reviews.
- Incorporate the KEV catalog into your risk‑based patch‑prioritization process (BOD 26‑04).
Source: CISA Advisory – 2026‑09‑11