Advisories
CISA Expands KEV Catalog with GitLab Path Traversal CVE-2026-85706
CISA has added CVE-2026-85706, a path‑traversal flaw in GitLab Community and Enterprise Editions, to its Known Exploited Vulnerabilities catalog after confirmed active exploitation. The move reinforces the agency’s push for rapid patching of high‑risk bugs under BOD 26‑04 and serves as a reminder for all organizations to prioritize KEV fixes.
CISA’s latest update to the Known Exploited Vulnerabilities (KEV) catalog brings a new entry that has already been weaponized in the wild. The flaw, CVE‑2026‑85706, allows attackers to traverse directories on GitLab servers, potentially gaining full control of the affected system.
What’s New?
The addition follows concrete evidence of active exploitation. By expanding the KEV list, CISA signals that this vulnerability is a high‑risk target for malicious actors and must be addressed with urgency.
Vulnerability Details
- Product: GitLab Community Edition & Enterprise Edition
- Exploit Type: Path traversal
- Impact: Full system compromise on exposed assets
- CVE ID: CVE‑2026‑85706
Implications for Federal Agencies
BOD 26‑04 mandates that Federal Civilian Executive Branch agencies prioritize remediation of KEV catalog CVEs on publicly exposed assets. The directive requires:
- Rapid patching of high‑risk vulnerabilities that grant total control after exploitation.
- Assessment of whether a system has been compromised before applying a fix.
- Deferred action on lower‑risk bugs, focusing resources where they matter most.
While the directive formally applies to federal agencies, CISA urges all organizations to adopt a similar risk‑based approach.
Next Steps & Reporting
Agencies and security teams should:
- Verify if their GitLab installations are affected and apply the latest patch immediately.
- Conduct a post‑mortem to confirm whether the system was already compromised.
- Submit any other exploited vulnerabilities not yet in the KEV catalog via the KEV Nomination Form—evidence of exploitation, a CVE ID, and clear mitigation guidance are required.
“CISA will continue to add vulnerabilities that meet the criteria of active exploitation, keeping the catalog current and actionable,” a CISA spokesperson said.