#16 · Briefing ·

Unpatched GitLab Servers Exposed Globally

A critical path traversal vulnerability in self-managed GitLab servers has prompted emergency patches and a federal catalog listing amid reports of thousands of exposed installations.

13,000+ servers exposing sensitive keys
AI-generated illustration. 13,000+ servers exposing sensitive keys

A critical path traversal vulnerability has been identified in self-managed GitLab servers, tracked as CVE-2026-85706. This security flaw carries the maximum Common Vulnerability Scoring System score of 10.0. The vulnerability allows remote actors without authentication to access and read arbitrary files stored on the affected servers, presenting a significant exposure risk for organizations running unpatched versions of the software.

According to reports from GitLab, the organization released emergency patches on September 10, 2026, to address the vulnerability in versions 19.1.8, 19.2.6, and 19.3.2. Following this release, the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on September 11, 2026. The threat intelligence platform Censys reported that public scans identified 86,231 exposed GitLab servers globally, with the highest concentration in China at 19,435 hosts, followed by the United States with 13,242 hosts. Censys also stated that there are at least 12 distinct public repositories hosting exploit code designed to target these unpatched instances.

This security issue matters because it exposes sensitive configuration data to external exploitation. The critical path traversal flaw enables unauthorized remote attackers to read arbitrary files from affected self-managed servers. Public exploit code has demonstrated the specific capability to read sensitive files such as gitlab-secrets.json, which contains the encryption keys used for CI/CD variables. The potential exposure of these keys could allow attackers to compromise broader development pipelines and access credentials utilized within affected enterprise environments.

Regarding the scale of the threat, different monitoring organizations have provided varying assessments. While Censys documented over 86,000 globally exposed servers, the Shadowserver Foundation reported data indicating that at least 13,700 of these exposed GitLab servers remain actively vulnerable to the exploit. Security researchers have noted that the availability of multiple public exploit repositories increases the likelihood of widespread opportunistic attacks against entities that fail to apply the emergency updates.

What remains unknown is the exact total number of vulnerable servers currently active online, as different scanning methodologies yield varying estimates. The Shadowserver Foundation estimates at least 13,700 vulnerable systems, whereas country-specific breakdowns from other threat intelligence reports sometimes sum to lower figures. Additionally, the full extent of active exploitation and the specific identities of compromised organizations have not been fully confirmed.

Sources

Verified claims

Original reporting: https://cybernews.com/security/gitlab-attackers-find-thousands-exposed-servers/

Written by The Quiet Search. Method: /about.

Related

Comments

Plain text only. New comments stay hidden until a person reviews them.