Hackers have begun exploiting a serious vulnerability in a popular software development tool, the Cybersecurity and Infrastructure Security Agency is warning.
CISA on Friday listed the vulnerability in GitLab’s development platform in its Known Exploited Vulnerabilities catalog, giving federal agencies until Monday to mitigate the risks associated with the flaw.
The vulnerability, tracked as CVE-2026-85706, involves a lack of authentication requirements and a lack of restrictions on where users can place files. Malicious actors could exploit the flaw to access files on GitLab servers without authorization. GitLab released a patch for the flaw on Sept. 10.
In issuing a CVE for the vulnerability, GitLab assigned it the maximum score of 10, indicating a critical flaw that organizations should patch as soon as possible. But for some organizations, it is already too late.
The cybersecurity firm watchTowr said on Friday that its intelligence analysts were “already observing in-the-wild probes” for servers running vulnerable versions of GitLab. The firm warned that hackers could use the flaw to “read local files and configs to obtain credentials, secrets, and sensitive information.”
“Based on recent GitLab vulnerabilities,” watchTowr added, “we know the time until indiscriminate exploitation is likely not far away.”
Hong Kong’s computer emergency response team released an advisory about the flaw on Monday, warning that it was “being exploited in the wild.”
In its security update on Thursday, GitLab also patched a second vulnerability, CVE-2026-87719, which could have allowed attackers to obtain sensitive information from servers running GitLab’s enterprise edition.
The new vulnerabilities are the latest major security weaknesses in GitLab’s products. The company disclosed CVE-2025-0376 in early 2025, as well as three more — CVE-2026-1092, CVE-2025-12664 and CVE-2026-5173 — in April. GitLab disclosed another critical flaw, CVE-2026-19478, in August, prompting hackers to begin exploiting it within days.