CISA Adds CVE-2026-85706 GitLab Path Traversal to Known Exploited Vulnerabilities Catalog
On September 11, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects GitLab Community Edition and GitLab Enterprise Edition and involves a path traversal flaw. CISA cited evidence of active exploitation in the wild. The inclusion triggers requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies to prioritize rapid remediation on publicly exposed assets.
