GitLab security advisory (AV26-917)
Brief
Serial Number: AV26-917
Date: September 11, 2026
As of September 10, 2026, GitLab is affected by vulnerabilities in the following product:
- GitLab
- Prior to 19.1.8
- Prior to 19.2.6
- Prior to 19.3.2
On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8
- GitLab Docs
- GitLab release notes
- GitLab Docs
- CISA KEV: CVE-2026-85706
GitLab security advisory (AV26-917) - Canadian Centre for Cyber Security
