GitLab users are being strongly advised to apply patches for a critical-severity vulnerability, identified as CVE-2026-85706, following reports of its exploitation in the wild. This flaw, described as a path traversal vulnerability, allows unauthenticated users to read arbitrary files from the GitLab server under specific conditions, according to Infosecurity Magazine..The vulnerability, fixed by GitLab on September 10, affects multiple versions of GitLab Community Edition and Enterprise Edition. Cybersecurity vendor Watchtower detected "in-the-wild probes" for the bug shortly after its disclosure, warning that widespread exploitation is likely imminent. They recommend organizations with public-facing self-hosted GitLab instances patch immediately or restrict public access, and suggest monitoring logs for specific HTTP POST requests to the repository commits API.The US Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog, mandating civilian federal agencies to remediate it by September 15. While primarily a directive for federal agencies, CISA recommends it as best practice for the private sector. This incident highlights the ongoing threat landscape where vulnerabilities are rapidly exploited, with AI potentially accelerating the discovery and weaponization of new flaws.Source: Infosecurity Magazine