Application Security

GitLab Path Traversal Vulnerability Added to CISA Known Exploited Flaws Catalog

FORTSECURE GLOBAL· 2026-09-13🛰 CISA Cybersecurity Advisories
#Application Security#Vulnerability#DevSecOps#Cybersecurity

CISA has warned organizations of active exploitation targeting a critical path traversal vulnerability in GitLab Community and Enterprise Editions.

GitLab Vulnerability Under Active Weaponization\n\nA critical path traversal flaw tracked as CVE-2026-85706, affecting both GitLab Community Edition (CE) and Enterprise Edition (EE), has been officially added to CISA's Known Exploited Vulnerabilities (KEV) Catalog. CISA confirmed that threat actors are actively leveraging this flaw to breach targeted networks and execute malicious operations.\n\nPath traversal vulnerabilities typically allow unauthenticated or low-privileged actors to traverse directory boundaries within the host filesystem. In the context of a central DevOps platform like GitLab, this can lead to unauthorized source code exposure, exfiltration of pipeline secrets, and potential arbitrary code execution, severely jeopardizing downstream deployment integrity.\n\n## FORTSECURE GLOBAL Recommendations\n\nDevelopment and security operations teams must prioritize defending their source control management infrastructure:\n\n- Patch Immediately: Update self-hosted GitLab deployments immediately to the designated remediation releases across supported software channels.\n- Protect CI/CD Secrets: Rotate API keys, deployment tokens, and cryptographic certificates integrated with GitLab pipelines in case instances have experienced unauthorized exposure.\n- Enforce Strict Network Segmentation: Restrict web access to GitLab administrative dashboards using VPNs, IP whitelisting, or Zero Trust Network Access (ZTNA) policies.


แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Fri, 11 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Fri, 11 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog