Summary
CISA has confirmed that CVE-2026-85706, the maximum-severity path traversal vulnerability in GitLab CE/EE documented in TTO-2026-0912-121, is being actively exploited in attacks as of September 14, 2026 — the date of the CISA federal agency remediation deadline under Binding Operational Directive 26-04. Organizations running self-managed GitLab instances on unpatched versions remain at immediate risk. The remediation guidance from TTO-2026-0912-121 is unchanged: upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately and rotate any credentials accessible from the server filesystem.
Timeline
| Date | Event |
|---|---|
| Sep 11, 2026 | GitLab patches CVE-2026-85706; WatchTowr honeypot confirms probes within hours |
| Sep 11, 2026 | CISA adds CVE-2026-85706 to KEV catalog; sets Sep 14 federal remediation deadline |
| Sep 12, 2026 | TTO-2026-0912-121 published; public PoC circulating |
| Sep 14, 2026 | CISA confirms active exploitation in attacks; federal remediation deadline reached |
What Changed
TTO-2026-0912-121 documented CVE-2026-85706 as a maximum-severity vulnerability with active internet-wide probes and a public PoC exploit, under a CISA imminent exploitation classification. As of September 14 CISA has upgraded its classification to confirmed active exploitation, meaning threat actors are using the vulnerability in real intrusion campaigns against production systems — not merely probing for vulnerable instances.
The distinction matters for triage priority. Probing indicates attackers are mapping the attack surface. Confirmed exploitation indicates they are breaching specific targets. Organizations that have not yet patched should treat this as an emergency remediation. Forensic triage of potentially exposed systems is also warranted: a system that was reachable while vulnerable may have been accessed before patching and should be treated as potentially compromised until evidence demonstrates otherwise.
Domain Intelligence
gitlab.com — 73.27
Score unchanged from TTO-2026-0912-121. gitlab.com scores at 73.27 in the high-trust range. GitLab is the vendor that patched CVE-2026-85706 on September 11, 2026.
The Trust Observatory · thetrustobservatory.com · September 14, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026