rootpwn

Advisories

CISA Adds GitLab Path Traversal CVE‑2026‑85706 to KEV Catalog, Urges Rapid Patch

CISA has added CVE‑2026‑85706, a path‑traversal flaw in GitLab Community and Enterprise Editions, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The update reinforces BOD‑26‑04, which requires federal civilian agencies to prioritize remediation of high‑risk KEVs on exposed assets. All organizations should patch immediately and can submit other KEV candidates via CISA’s nomination form.

New KEV Entry

CISA’s latest addition to the Known Exploited Vulnerabilities (KEV) catalog is CVE‑2026‑85706, a path‑traversal vulnerability that allows attackers to read arbitrary files on GitLab servers. The flaw is present in both Community Edition (CE) and Enterprise Edition (EE) and has been actively exploited in the wild.

Why It Matters for Federal Agencies

Binding Operational Directive (BOD) 26‑04: Prioritizing Security Updates Based on Risk mandates that Federal Civilian Executive Branch (FCEB) agencies treat KEV‑listed CVEs as high‑risk. Agencies must:

  • Apply patches on publicly exposed GitLab instances immediately.
  • Verify whether a system has been compromised before a patch is deployed.
  • Defer lower‑risk vulnerabilities until the high‑risk ones are remediated.

While BOD 26‑04 applies only to FCEB agencies, CISA encourages all organizations to adopt a risk‑based approach and prioritize KEV remediation.

How to Get Involved

Organizations that discover an actively exploited vulnerability not yet in the KEV catalog can submit it via CISA’s KEV Nomination Form. Submissions must include a CVE ID, proof of exploitation, and clear mitigation guidance.

"CISA will continue to add vulnerabilities to the catalog that meet the specified criteria."

Take Action Now

Patch GitLab installations, validate that the patch is in place, and check for signs of compromise. If you suspect a related exploit, report it immediately to CISA.

CISA KEV GitLab Path Traversal CVE-2026-85706 Federal Agencies Patch Management

← All news