Maximum Severity GitLab Flaw Puts Supply Chains at Risk
Summary
A critical path traversal vulnerability, designated CVE-2026-85706, has been discovered in GitLab Community Edition and Enterprise Edition. This flaw carries a maximum CVSS score of 10.0, indicating a severe risk to users.
IFF Assessment
A critical vulnerability with a high CVSS score in a widely used development platform poses a significant threat to software supply chains and organizations relying on GitLab.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or mitigating this vulnerability in their GitLab instances immediately. The severity of this flaw means attackers could potentially gain significant access, compromising code repositories and downstream projects, thus impacting the entire software supply chain.