TTO-2026-0914-125 · September 14, 2026 Active ExploitationFollow-Up

GitLab CVE-2026-85706 Confirmed Exploited in Attacks Past CISA Deadline — Updates TTO-2026-0912-121

gitlab.comCVE-2026-85706 CVSS 10.0CISA KEV deadline passedActive exploitation confirmedUpdates TTO-2026-0912-121

Summary

CISA has confirmed that CVE-2026-85706, the maximum-severity path traversal vulnerability in GitLab CE/EE documented in TTO-2026-0912-121, is being actively exploited in attacks as of September 14, 2026 — the date of the CISA federal agency remediation deadline under Binding Operational Directive 26-04. Organizations running self-managed GitLab instances on unpatched versions remain at immediate risk. The remediation guidance from TTO-2026-0912-121 is unchanged: upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately and rotate any credentials accessible from the server filesystem.

Timeline

DateEvent
Sep 11, 2026GitLab patches CVE-2026-85706; WatchTowr honeypot confirms probes within hours
Sep 11, 2026CISA adds CVE-2026-85706 to KEV catalog; sets Sep 14 federal remediation deadline
Sep 12, 2026TTO-2026-0912-121 published; public PoC circulating
Sep 14, 2026CISA confirms active exploitation in attacks; federal remediation deadline reached

What Changed

TTO-2026-0912-121 documented CVE-2026-85706 as a maximum-severity vulnerability with active internet-wide probes and a public PoC exploit, under a CISA imminent exploitation classification. As of September 14 CISA has upgraded its classification to confirmed active exploitation, meaning threat actors are using the vulnerability in real intrusion campaigns against production systems — not merely probing for vulnerable instances.

The distinction matters for triage priority. Probing indicates attackers are mapping the attack surface. Confirmed exploitation indicates they are breaching specific targets. Organizations that have not yet patched should treat this as an emergency remediation. Forensic triage of potentially exposed systems is also warranted: a system that was reachable while vulnerable may have been accessed before patching and should be treated as potentially compromised until evidence demonstrates otherwise.

Domain Intelligence

gitlab.com — 73.27

Score unchanged from TTO-2026-0912-121. gitlab.com scores at 73.27 in the high-trust range. GitLab is the vendor that patched CVE-2026-85706 on September 11, 2026.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 14, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026