Exploit
Kritieke kwetsbaarheid in GitLab wordt actief misbruikt: update nu
Key Facts
Signal Type
Exploit
Industry
Cybersecurity
Companies
GitLab
Date
September 12, 2026
On [date], the NCSC Netherlands issued an advisory for a critical vulnerability in GitLab CE/EE, tracked as CVE-2026-85706 with a CVSS score of 10.0. The flaw allows unauthenticated attackers to send specially crafted requests over the internet to read files on a vulnerable GitLab server. Public exploit code is already available, and active exploitation has been confirmed.
Any organization running a self-managed GitLab instance on versions prior to 19.1.8, 19.2.6, or 19.3.2 is at risk. GitLab.com and GitLab Dedicated users are not affected as they have been patched automatically. The advisory specifically warns of potential exposure of confidential data including passwords, access keys, and source code.
Monitor for proof-of-concept exploit code being weaponized further. Check for any coverage from major cybersecurity vendors. The incident may lead to increased compliance scrutiny for self-managed GitLab deployments. Sales reps should track which accounts are on affected versions and reach out with relevant patch guidance.
Source:
NCSC Netherlands NewsGet cybersecurity signals in your CRM
Data breaches, ransomware events, funding rounds, and M&A across security vendors and targets.
