Malicious activity surrounding GitLab’s latest Critical security vulnerability continues to surge, with threat actors now observed moving from reconnaissance to outright data theft.
"Exploitation [of CVE-2026-85706] quickly escalated on Friday from behavioural probes to identifying vulnerable instances, all the way to successful exploitation leading to exfiltration of sensitive files, all before the vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog,” watchTowr’s head of threat intelligence, Jake Knott, told Cyber Daily overnight.
“Over the weekend, we also observed threat actors dumping config files for secrets along with system SSH configurations for the victim system.
“The combination is, as you can imagine, potent, as it may allow threat actors the ability to extract passwords, connect to instances that allow password authentication and gain access to the host under the right conditions.”
watchTowr is urging security teams to patch, investigate, and be aware of any malicious changes or activity.
Cyber security firm Rapid7 is also tracking the activity surrounding CVE-2026-85706 and the urgency the US cyber agency is recommending when addressing the vulnerability.
“CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04,” Rapid7 said in a September 14 blog post.
However, it’s not just government agencies that need to act. According to Rapid7, any organisation running an affected self-managed GitLab instance should “remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles”.
GitLab Dedicated customers are fine, as GitLab is already running a patched version, unsurprisingly. All self-managed deployment types – such as Omnibus, source code, and Helm chart – are all in the firing line.
GitLab’s latest patch didn’t just address CVE-2026-85706; however, as of the time of writing, that is the only vulnerability facing exploitation. And there are certainly some worrying vulnerabilities in the mix.
“These include CVE-2026-87719, a critical insecure deserialisation vulnerability (CWE-502) in GitLab EE with a CVSSv3.1 score of 9.9,” Rapid7 said.
“GitLab states that, under certain conditions, an authenticated user with Duo Chat access could obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument.”
Regardless, the bottom line remains the same. Patch now, before it’s too late, and security teams should stay vigilant.
“Given the confirmed exploitation, Rapid7 strongly recommends looking for signs of compromise even after the update has been applied.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.